Skip to main content
HIGH

CVE-2022-28213

CVSS v3

8.1

HIGH

EPSS Score

12.5 %

exploit probability, as of 2026-10-05

CISA KEV

No

known exploited

Exploitation

—

SSVC status

Description

When a user access SOAP Web services in SAP BusinessObjects Business Intelligence Platform - version 420, 430, it does not sufficiently validate the XML document accepted from an untrusted source, which might result in arbitrary files retrieval from the server and in successful exploits of DoS.

Technical details

Published
2022-04-12
Exploit-DB
EDB-50900

Frequently asked questions

What is CVE-2022-28213?

When a user access SOAP Web services in SAP BusinessObjects Business Intelligence Platform - version 420, 430, it does not sufficiently validate the XML document accepted from an untrusted source, which might result in arbitrary files retrieval from the server and in successful exploits of DoS.

Is CVE-2022-28213 actively exploited?

Active exploitation of CVE-2022-28213 has not been confirmed. Its EPSS score was 12.5% on 2026-10-05, the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2022-28213?

CVE-2022-28213 has a CVSS v3 base score of 8.1 (HIGH severity).

Is CVE-2022-28213 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.

No credit card required · 50 free checks/month · Free API key