CVE-2022-28213
Summary
| CVE | CVE-2022-28213 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-04-12 17:15:00 UTC |
| Updated | 2022-09-09 16:47:00 UTC |
| Description | When a user access SOAP Web services in SAP BusinessObjects Business Intelligence Platform - version 420, 430, it does not sufficiently validate the XML document accepted from an untrusted source, which might result in arbitrary files retrieval from the server and in successful exploits of DoS. |
Risk And Classification
Problem Types: CWE-112
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Sap | Businessobjects Business Intelligence Platform | 420 | All | All | All |
| Application | Sap | Businessobjects Business Intelligence Platform | 430 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| SAP BusinessObjects Intelligence 4.3 XML Injection ≈ Packet Storm | MISC | packetstormsecurity.com | |
| Access Denied | MISC | www.sap.com | |
| launchpad.support.sap.com | MISC | launchpad.support.sap.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.