CVE-2022-28213
SAP BusinessObjects Intelligence 4.3 - XML External Entity (XXE)
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
2Exploited in Wild
-Decision
Descriptions
When a user access SOAP Web services in SAP BusinessObjects Business Intelligence Platform - version 420, 430, it does not sufficiently validate the XML document accepted from an untrusted source, which might result in arbitrary files retrieval from the server and in successful exploits of DoS.
Cuando un usuario accede a servicios web SOAP en SAP BusinessObjects Business Intelligence Platform - versión 420, 430, no se comprueba suficientemente el documento XML aceptado desde una fuente no confiable, lo que podría resultar en una recuperación de archivos arbitrarios desde el servidor y a explotaciones con éxito de DoS
SAP BusinessObjects Intelligence version 4.3 suffers from an XML external entity injection vulnerability.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2022-03-30 CVE Reserved
- 2022-04-12 CVE Published
- 2022-05-11 First Exploit
- 2024-01-30 EPSS Updated
- 2024-08-03 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-112: Missing XML Validation
CAPEC
References (3)
URL | Tag | Source |
---|
URL | Date | SRC |
---|---|---|
https://www.exploit-db.com/exploits/50900 | 2022-05-11 | |
http://packetstormsecurity.com/files/167046/SAP-BusinessObjects-Intelligence-4.3-XML-Injection.html | 2024-08-03 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://www.sap.com/documents/2022/02/fa865ea4-167e-0010-bca6-c68f7e60039b.html | 2022-09-09 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Sap Search vendor "Sap" | Businessobjects Business Intelligence Platform Search vendor "Sap" for product "Businessobjects Business Intelligence Platform" | 420 Search vendor "Sap" for product "Businessobjects Business Intelligence Platform" and version "420" | - |
Affected
| ||||||
Sap Search vendor "Sap" | Businessobjects Business Intelligence Platform Search vendor "Sap" for product "Businessobjects Business Intelligence Platform" | 430 Search vendor "Sap" for product "Businessobjects Business Intelligence Platform" and version "430" | - |
Affected
|