CVE-2022-28217
CVE-2022-28217
Vexday Risk Score
3Bajo
Decisión SSVC (CISA)
Track
Sin señal de explotación → monitorear
CVSS —EPSS 0.7%KEV nãoPoC —Nuclei —Metasploit —Patch —
Ciclo de vida
13 jun 2022Publicada en NVD
Recomendación: Monitorear — sin señal de explotación por ahora.
Some part of SAP NetWeaver (EP Web Page Composer) does not sufficiently validate an XML document accepted from an untrusted source, which allows an adversary to exploit unprotected XML parking at endpoints, and a possibility to conduct SSRF attacks that could compromise system�s Availability by causing system to crash.
Productos afectados
SAP SE · SAP NetWeaver (EP Web Page Composer)¿Quieres saber si tu infraestructura está expuesta a esto?
Hablar con TrueHacking →