vendor:
BusinessObjects Intelligence
by:
West Shepherd
8.1
CVSS
HIGH
XML External Entity (XXE)
611
CWE
Product Name: BusinessObjects Intelligence
Affected Version From: 4.2
Affected Version To: 4.3
Patch Exists: YES
Related CWE: CVE-2022-28213
CPE: a:sap:businessobjects_intelligence:4.3
Platforms Tested: Windows Server 2019 x64
2022
SAP BusinessObjects Intelligence 4.3 – XML External Entity (XXE)
SAP BusinessObjects Intelligence 4.3 is vulnerable to XML External Entity (XXE) attacks. An attacker can send a specially crafted XML request to the application, which can then be used to read arbitrary files on the server or perform remote requests. The attacker can also use the XXE vulnerability to perform server-side request forgery (SSRF) attacks.
Mitigation:
The application should be configured to disable XML external entity (XXE) processing. The application should also be configured to disable DTDs (Document Type Definitions) completely.