Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

SAP Mobile Platform XXE vulnerability (import MBO applications), SAP security note 2152227

SAP Note 2152227High priority

SAP security note 2152227, "SAP Mobile Platform XXE vulnerability (import MBO applications)", is a program error note released on August 11, 2015. Below are the symptom, SAP recommended solution and the affected software components.

CategoryProgram Error
PriorityCorrection with High Priority
StatusReleased for Customer
Released onAugust 11, 2015

Description

Symptom

SAP Security Note 2152227 addresses an XML External Entity (XXE) vulnerability in the SAP Mobile Platform (SMP) when importing Mobile Business Objects (MBO) applications. This vulnerability allows an attacker to potentially execute a denial of service (DoS) attack or make unauthorized HTTP GET requests to other servers within the network, which might otherwise be inaccessible.

When importing an MBO application to SMP 2.x or using the MBO side-car feature in SMP 3.0, a maliciously crafted XML document within a ZIP-formatted file can exploit the XXE vulnerability. This can lead to a denial of service on the SMP server or enable the attacker to make HTTP GET requests to other internal servers.

Solution

To mitigate this vulnerability, upgrade your SMP server to one of the following versions:

  • SMP 2.2.7
  • SMP 2.3.6
  • SMP 3.0.8

CVSS

Score 4.9 / 10 Vector: AV:N/AC:M/PR:S/C:P/I:N/A:P

Affected components

  • SMP 2.2.x up to before 2.2.7
  • SMP 2.3.x up to before 2.3.6
  • SMP 3.0.x up to before 3.0.8

Full note on SAP: SAP Support Launchpad note 2152227

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More