Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-jqcq-m297-wggx

Опубликовано: 14 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 9.6

Описание

SAP Business One for Android 1.2.3 allows remote attackers to conduct XML External Entity (XXE) attacks via crafted XML data in a request to B1iXcellerator/exec/soap/vP.001sap0003.in_WCSX/com.sap.b1i.vplatform.runtime/INB_WS_CALL_SYNC_XPT/INB_WS_CALL_SYNC_XPT.ipo/proc, aka SAP Security Note 2378065.

SAP Business One for Android 1.2.3 allows remote attackers to conduct XML External Entity (XXE) attacks via crafted XML data in a request to B1iXcellerator/exec/soap/vP.001sap0003.in_WCSX/com.sap.b1i.vplatform.runtime/INB_WS_CALL_SYNC_XPT/INB_WS_CALL_SYNC_XPT.ipo/proc, aka SAP Security Note 2378065.

EPSS

Процентиль: 93%
0.10057
Средний

9.6 Critical

CVSS3

Дефекты

CWE-611

Связанные уязвимости

CVSS3: 9.6
nvd
больше 8 лет назад

SAP Business One for Android 1.2.3 allows remote attackers to conduct XML External Entity (XXE) attacks via crafted XML data in a request to B1iXcellerator/exec/soap/vP.001sap0003.in_WCSX/com.sap.b1i.vplatform.runtime/INB_WS_CALL_SYNC_XPT/INB_WS_CALL_SYNC_XPT.ipo/proc, aka SAP Security Note 2378065.

EPSS

Процентиль: 93%
0.10057
Средний

9.6 Critical

CVSS3

Дефекты

CWE-611