Server Side Request Forgery Vulnerability in SAP NetWeaver Products
CVE-2017-16678
4.7MEDIUM
Key Information:
- Vendor
SAP
- Vendor
- CVE Published:
- 12 December 2017
What is CVE-2017-16678?
This vulnerability allows an attacker to exploit the SAP NetWeaver Knowledge Management Configuration Service and KMC-BC components by sending specially crafted requests on behalf of the vulnerable application. The flaw can potentially lead to unauthorized access to internal resources, enabling further malicious activities against an organization's infrastructure.
Affected Version(s)
SAP NetWeaver Knowledge Management Configuration Service EPBC and EPBC2 from 7.00 to 7.02; KMC-BC 7.30, 7.31, 7.40 and 7.50