← back
CVE-2022-28213CWE-112

CVE-2022-28213

28Vexday Risk Score

No sign of exploitation. It has a public proof of concept.

ssvc Attendepss 12%
from disclosure to weapon29 days
Published on NVDApr 12
1st PoC+29d
exploitation probability
12%top 4% of all CVEs
observed exploitation
nono source reports it
2 public exploit(s)
When a user access SOAP Web services in SAP BusinessObjects Business Intelligence Platform - version 420, 430, it does not sufficiently validate the XML document accepted from an untrusted source, which might result in arbitrary files retrieval from the server and in successful exploits of DoS.
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.