5.5
CVSSv2

CVE-2022-28213

Published: 12/04/2022 Updated: 09/09/2022
CVSS v2 Base Score: 5.5 | Impact Score: 4.9 | Exploitability Score: 8
CVSS v3 Base Score: 8.1 | Impact Score: 5.2 | Exploitability Score: 2.8
VMScore: 490
Vector: AV:N/AC:L/Au:S/C:P/I:N/A:P

Vulnerability Summary

When a user access SOAP Web services in SAP BusinessObjects Business Intelligence Platform - version 420, 430, it does not sufficiently validate the XML document accepted from an untrusted source, which might result in arbitrary files retrieval from the server and in successful exploits of DoS.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

sap businessobjects business intelligence platform 420

sap businessobjects business intelligence platform 430

Exploits

SAP BusinessObjects Intelligence version 43 suffers from an XML external entity injection vulnerability ...