CVE-2022-28213
When a user access SOAP Web services in SAP BusinessObjects Business Intelligence Platform - version 420, 430, it does not sufficiently validate the XML document accepted from an untrusted source, which might result in arbitrary files retrieval from the…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 12.5%, higher than 96% of all known CVEs. Patch or mitigate before the next change window.
Description
When a user access SOAP Web services in SAP BusinessObjects Business Intelligence Platform - version 420, 430, it does not sufficiently validate the XML document accepted from an untrusted source, which might result in arbitrary files retrieval from the server and in successful exploits of DoS.
- CVSS 3.1
- 8.1 HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
- EPSS
- 12.48% probability · 96th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-112
- Affected
- sap/businessobjects business intelligence platform
- Source
- cna@sap.com
References
- http://packetstormsecurity.com/files/167046/SAP-BusinessObjects-Intelligence-4.3-XML-Injection.htmlExploit, Third Party Advisory, VDB Entry
- https://launchpad.support.sap.com/#/notes/3055044Permissions Required, Vendor Advisory
- https://www.sap.com/documents/2022/02/fa865ea4-167e-0010-bca6-c68f7e60039b.htmlVendor Advisory
- http://packetstormsecurity.com/files/167046/SAP-BusinessObjects-Intelligence-4.3-XML-Injection.htmlExploit, Third Party Advisory, VDB Entry
- https://launchpad.support.sap.com/#/notes/3055044Permissions Required, Vendor Advisory
- https://www.sap.com/documents/2022/02/fa865ea4-167e-0010-bca6-c68f7e60039b.htmlVendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.