SAP Business One for Android 1.2.3 allows remote attackers to conduct XML External Entity (XXE) attacks via crafted XML data in a request to B1iXcellerator/exec/soap/vP.001sap0003.in_WCSX/com.sap.b1i.vplatform.runtime/INB_WS_CALL_SYNC_XPT/INB_WS_CALL_SYNC_XPT.ipo/proc, aka SAP Security Note 2378065.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2017-05-25T19:00:00
Updated: 2024-08-06T01:22:20.653Z
Reserved: 2016-07-20T00:00:00
Link: CVE-2016-6256
Vulnrichment
No data.
NVD
Status : Modified
Published: 2017-05-26T01:29:00.240
Modified: 2024-11-21T02:55:45.460
Link: CVE-2016-6256
Redhat
No data.