PT-2024-3589 · Apache · Apache Zeppelin Sap

Kuiplatain

·

Published

2024-04-09

·

Updated

2025-05-05

·

CVE-2022-47894

CVSS v2.0

6.4

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:P
Name of the Vulnerable Software and Affected Versions Apache Zeppelin SAP versions 0.8.0 through 0.10.x
Description The issue is related to improper input validation, which can be exploited by a remote attacker to disclose protected information or cause a denial of service using a specially crafted XML request. This vulnerability affects products that are no longer supported by the maintainer.
Recommendations As a temporary workaround, consider restricting access to the instance to trusted users. Find an alternative to Apache Zeppelin SAP, as the project is retired and no fix will be released. Note that the fix was already merged into the source code, but due to the project's retirement, it will not be released as part of a new version.

Fix

XXE

RCE

Weakness Enumeration

Related Identifiers

BDU:2024-03895
CVE-2022-47894
GHSA-RR59-H6RH-V84V

Affected Products

Apache Zeppelin Sap