Description
SOAP Web Services in SAP BO BIP has an XXE vulnerability. This vulnerability allows an attacker to send crafted requests to a web application for extraction of secrets from the file system, server-side request forgery or denial-of-service attacks.
Remediation
Upgrade to the latest version of SAP BO BIP
References
Related Vulnerabilities
Liferay DXP Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2024-26273)
MySQL CVE-2014-0427 Vulnerability (CVE-2014-0427)
Grafana Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2019-19499)
PHP Permissions, Privileges, and Access Controls Vulnerability (CVE-2012-3365)