CVE-2022-28213 Information

Description

When a user access SOAP Web services in SAP BusinessObjects Business Intelligence Platform - version 420 430 it does not sufficiently validate the XML document accepted from an untrusted source which might result in arbitrary files retrieval from the server and in successful exploits of DoS.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H

Reference

https://launchpad.support.sap.com/#/notes/3055044 https://www.sap.com/documents/2022/02/fa865ea4-167e-0010-bca6-c68f7e60039b.html http://packetstormsecurity.com/files/167046/SAP-BusinessObjects-Intelligence-4.3-XML-Injection.html

Attack Complexity

LOW

Privileges Required

LOW

User Interaction Required

LOW

Scope

NONE

Confidentiality Impact

UNCHANGED

Integrity Impact

HIGH

Availability Impact

NONE

Base Score

HIGH

Base Severity

8.1

Share on: