SAP security note 2152227, "SAP Mobile Platform XXE vulnerability (import MBO applications)", is a program error note released on August 11, 2015. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
SAP Security Note 2152227 addresses an XML External Entity (XXE) vulnerability in the SAP Mobile Platform (SMP) when importing Mobile Business Objects (MBO) applications. This vulnerability allows an attacker to potentially execute a denial of service (DoS) attack or make unauthorized HTTP GET requests to other servers within the network, which might otherwise be inaccessible.
When importing an MBO application to SMP 2.x or using the MBO side-car feature in SMP 3.0, a maliciously crafted XML document within a ZIP-formatted file can exploit the XXE vulnerability. This can lead to a denial of service on the SMP server or enable the attacker to make HTTP GET requests to other internal servers.
Solution
To mitigate this vulnerability, upgrade your SMP server to one of the following versions:
- SMP 2.2.7
- SMP 2.3.6
- SMP 3.0.8
CVSS
Score 4.9 / 10 Vector: AV:N/AC:M/PR:S/C:P/I:N/A:P
Affected components
- SMP 2.2.x up to before 2.2.7
- SMP 2.3.x up to before 2.3.6
- SMP 3.0.x up to before 3.0.8
Full note on SAP: SAP Support Launchpad note 2152227
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].




