CVE-2022-28213 is a high-severity XML External Entity (XXE) vulnerability affecting SAP BusinessObjects Business Intelligence Platform versions 420 and 430. It allows authenticated attackers to retrieve arbitrary files from the server and potentially cause Denial of Service (DoS) by exploiting insufficient XML document validation in SOAP Web services. With a CVSS score of 8.1, this vulnerability is easily exploitable over the network with low privileges and no user interaction. While not currently on CISA's KEV catalog or widely discussed, public exploit code (EDB-50900) exists, indicating a potential for future exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
420CPE matchmatch criteria | cpe:2.3:a:sap:businessobjects_business_intelligence_platform:420:*:*:*:*:*:*:* | ||
430CPE matchmatch criteria | cpe:2.3:a:sap:businessobjects_business_intelligence_platform:430:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.