SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2022-28217

Some part of SAP NetWeaver (EP Web Page Composer) does not sufficiently validate an XML document accepted from an untrusted source, which allows an adversary to exploit unprotected XML parking at endpoints, and a possibility to conduct SSRF attacks that…

MEDIUM 6.5EPSS 0.74%

Does this matter?

Lower severity and a low EPSS score (0.74%). Track it; it rarely justifies an emergency change on its own.

Description

Some part of SAP NetWeaver (EP Web Page Composer) does not sufficiently validate an XML document accepted from an untrusted source, which allows an adversary to exploit unprotected XML parking at endpoints, and a possibility to conduct SSRF attacks that could compromise system�s Availability by causing system to crash.

CVSS 3.1
6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
EPSS
0.74% probability · 53th percentile
CISA KEV
Not listed
Weakness
CWE-918
Affected
sap/netweaver
Source
cna@sap.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.