CVE-2017-16678
Server Side Request Forgery (SSRF) vulnerability in SAP NetWeaver Knowledge Management Configuration Service, EPBC and EPBC2 from 7.00 to 7.02; KMC-BC 7.30, 7.31, 7.40 and 7.50, that allows an attacker to manipulate the vulnerable application to send…
Does this matter?
Lower severity and a low EPSS score (0.87%). Track it; it rarely justifies an emergency change on its own.
Description
Server Side Request Forgery (SSRF) vulnerability in SAP NetWeaver Knowledge Management Configuration Service, EPBC and EPBC2 from 7.00 to 7.02; KMC-BC 7.30, 7.31, 7.40 and 7.50, that allows an attacker to manipulate the vulnerable application to send crafted requests on behalf of the application.
- CVSS 3.0
- 4.7 MEDIUMCVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L
- EPSS
- 0.87% probability · 57th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-918
- Affected
- sap/netweaver knowledge management configuration service · sap/epbc · sap/epbc2 · sap/kmc-bc
- Source
- cna@sap.com
References
- http://www.securityfocus.com/bid/102149Third Party Advisory, VDB Entry
- https://blogs.sap.com/2017/12/12/sap-security-patch-day-december-2017/Vendor Advisory
- https://launchpad.support.sap.com/#/notes/2457562Permissions Required
- http://www.securityfocus.com/bid/102149Third Party Advisory, VDB Entry
- https://blogs.sap.com/2017/12/12/sap-security-patch-day-december-2017/Vendor Advisory
- https://launchpad.support.sap.com/#/notes/2457562Permissions Required
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.