CVE-2022-28213
CVSS v3
8.1
HIGH
EPSS Score
12.5 %
exploit probability, as of 2026-10-05
CISA KEV
No
known exploited
Exploitation
—
SSVC status
Description
When a user access SOAP Web services in SAP BusinessObjects Business Intelligence Platform - version 420, 430, it does not sufficiently validate the XML document accepted from an untrusted source, which might result in arbitrary files retrieval from the server and in successful exploits of DoS.
Technical details
- Published
- 2022-04-12
- Exploit-DB
- EDB-50900
Frequently asked questions
What is CVE-2022-28213?
When a user access SOAP Web services in SAP BusinessObjects Business Intelligence Platform - version 420, 430, it does not sufficiently validate the XML document accepted from an untrusted source, which might result in arbitrary files retrieval from the server and in successful exploits of DoS.
Is CVE-2022-28213 actively exploited?
Active exploitation of CVE-2022-28213 has not been confirmed. Its EPSS score was 12.5% on 2026-10-05, the estimated probability of exploitation in the next 30 days.
What is the CVSS score for CVE-2022-28213?
CVE-2022-28213 has a CVSS v3 base score of 8.1 (HIGH severity).
Is CVE-2022-28213 affecting your environment?
Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.
No credit card required · 50 free checks/month · Free API key
Other 2022 vulnerabilities worth triaging
Ranked by exploit probability (EPSS).