Vulnerability Description
When a user access SOAP Web services in SAP BusinessObjects Business Intelligence Platform - version 420, 430, it does not sufficiently validate the XML document accepted from an untrusted source, which might result in arbitrary files retrieval from the server and in successful exploits of DoS.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Sap | Businessobjects Business Intelligence Platform | 420 |
Related Weaknesses (CWE)
References
- http://packetstormsecurity.com/files/167046/SAP-BusinessObjects-Intelligence-4.3ExploitThird Party AdvisoryVDB Entry
- https://launchpad.support.sap.com/#/notes/3055044Permissions RequiredVendor Advisory
- https://www.sap.com/documents/2022/02/fa865ea4-167e-0010-bca6-c68f7e60039b.htmlVendor Advisory
- http://packetstormsecurity.com/files/167046/SAP-BusinessObjects-Intelligence-4.3ExploitThird Party AdvisoryVDB Entry
- https://launchpad.support.sap.com/#/notes/3055044Permissions RequiredVendor Advisory
- https://www.sap.com/documents/2022/02/fa865ea4-167e-0010-bca6-c68f7e60039b.htmlVendor Advisory
FAQ
What is CVE-2022-28213?
CVE-2022-28213 is a vulnerability with a CVSS score of 8.1 (HIGH). When a user access SOAP Web services in SAP BusinessObjects Business Intelligence Platform - version 420, 430, it does not sufficiently validate the XML document accepted from an untrusted source, whi...
How severe is CVE-2022-28213?
CVE-2022-28213 has been rated HIGH with a CVSS base score of 8.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-28213?
Check the references section above for vendor advisories and patch information. Affected products include: Sap Businessobjects Business Intelligence Platform.