Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2017-16349

An exploitable XML external entity vulnerability exists in the reporting functionality of SAP BPC. A specially crafted XML request can cause an XML external entity to be referenced, resulting in information disclosure and potential denial of service. An attacker can issue authenticated HTTP requests to trigger this vulnerability.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.003
EPSS Ranking 55.5%
CVSS Severity
CVSS v3 Score 6.4
CVSS v2 Score 5.5
Products affected by CVE-2017-16349


Contact Us

Shodan ® - All rights reserved