HIGH

CVE-2022-28213

CVSS v3

8.1

HIGH

EPSS Score

12.6%

exploit probability

CISA KEV

No

known exploited

Exploitation

SSVC status

Description

When a user access SOAP Web services in SAP BusinessObjects Business Intelligence Platform - version 420, 430, it does not sufficiently validate the XML document accepted from an untrusted source, which might result in arbitrary files retrieval from the server and in successful exploits of DoS.

Technical details

Published
4/12/2022

Frequently asked questions

What is CVE-2022-28213?

When a user access SOAP Web services in SAP BusinessObjects Business Intelligence Platform - version 420, 430, it does not sufficiently validate the XML document accepted from an untrusted source, which might result in arbitrary files retrieval from the server and in successful exploits of DoS.

Is CVE-2022-28213 actively exploited?

Active exploitation of CVE-2022-28213 has not been confirmed. The EPSS score is 12.6%, indicating the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2022-28213?

CVE-2022-28213 has a CVSS v3 base score of 8.1 (HIGH severity).

Is CVE-2022-28213 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.