SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2020-6177

SAP Mobile Platform, version 3.0, does not sufficiently validate an XML document accepted from an untrusted source which could lead to partial denial of service.

MEDIUM 4.3EPSS 0.85%

Does this matter?

Lower severity and a low EPSS score (0.85%). Track it; it rarely justifies an emergency change on its own.

Description

SAP Mobile Platform, version 3.0, does not sufficiently validate an XML document accepted from an untrusted source which could lead to partial denial of service. Since SAP Mobile Platform does not allow External-Entity resolving, there is no issue of leaking content of files on the server.

CVSS 3.1
4.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
EPSS
0.85% probability · 56th percentile
CISA KEV
Not listed
Weakness
CWE-20
Affected
sap/mobile platform
Source
cna@sap.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.