SAP security note 2159601, "SAP Mobile Platform XXE (add repository)". Below are the symptom and SAP recommended solution.
Description
Symptom
A maliciously crafted XML document could exploit a misconfigured XML parser for processing EclipseLink p2 repository operations, possibly resulting in data disclosure or denial of service problems.
Solution
Apply patch SMP 3.0 SP07 PL01 to your SMP server installation.
Reason and prerequisites
The XML Parser and its settings are inherited from the EclipseLink component, which is part of the OSGi administration under the SMP server. The parser settings have been updated to prevent vulnerability to XXE attacks. To exploit the vulnerability, an attacker needs an authenticated session to SMP as an Administrator. This can be achieved by knowing the SMP Administrator's username and password or by stealing the session cookie of an authenticated administrator.
CVSS
Score 5.5 / 10 Vector: AV:N/AC:L/Au:S/C:P/I:N/A:P
Full note on SAP: SAP Support Launchpad note 2159601
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].




