PT-2022-18878 · Sap · Sap Businessobjects Business Intelligence Platform

Published

2022-04-12

·

Updated

2022-09-09

·

CVE-2022-28213

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
Name of the Vulnerable Software and Affected Versions SAP BusinessObjects Business Intelligence Platform versions 420, 430
Description The issue arises when a user accesses SOAP Web services, and the system fails to sufficiently validate the XML document accepted from an untrusted source. This could lead to the retrieval of arbitrary files from the server and potentially result in successful exploits of Denial of Service (DoS).
Recommendations For versions 420 and 430, consider restricting access to SOAP Web services until a fix is available. As a temporary workaround, restrict the acceptance of XML documents from untrusted sources to minimize the risk of exploitation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-28213

Affected Products

Sap Businessobjects Business Intelligence Platform