CVE-2022-27671
3Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackepss 1.3%
exploitation probability
1.3%top 31% of all CVEs
observed exploitation
nono source reports it
In short
A security token used to prevent attacks is exposed in the website's web address, allowing someone to see it. This can leak sensitive information if the URL is shared or logged.
Technical detail
CSRF tokens in URL parameters are susceptible to disclosure via HTTP Referer headers, browser history, logs, and proxies. This violates token confidentiality principles and may enable token reuse or session hijacking if tokens lack proper expiration or binding mechanisms.
Summary generated and translated by AI from the official description.
A CSRF token visible in the URL may possibly lead to information disclosure vulnerability.
Affected products
SAP SE · SAP BusinessObjects Business Intelligence Platform