CVE-2022-28213 Information
Jun 07, 2022
cve
Description
When a user access SOAP Web services in SAP BusinessObjects Business Intelligence Platform - version 420 430 it does not sufficiently validate the XML document accepted from an untrusted source which might result in arbitrary files retrieval from the server and in successful exploits of DoS.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
Reference
https://launchpad.support.sap.com/#/notes/3055044 https://www.sap.com/documents/2022/02/fa865ea4-167e-0010-bca6-c68f7e60039b.html http://packetstormsecurity.com/files/167046/SAP-BusinessObjects-Intelligence-4.3-XML-Injection.html
Attack Complexity
LOW
Privileges Required
LOW
User Interaction Required
LOW
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
NONE
Base Score
HIGH
Base Severity
8.1
Share on: