« Volver al listado

CVE-2017-16678

Estado: ModificadaMedia (4.7)—

Server Side Request Forgery (SSRF) vulnerability in SAP NetWeaver Knowledge Management Configuration Service, EPBC and EPBC2 from 7.00 to 7.02; KMC-BC 7.30, 7.31, 7.40 and 7.50, that allows an attacker to manipulate the vulnerable application to send crafted requests on behalf of the application.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (4)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2017-16678",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 6.5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:S/C:P/I:P/A:P",
          "authentication": "SINGLE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "LOW",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 6.4,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV30": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.0",
          "baseScore": 4.7,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L",
          "integrityImpact": "LOW",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "LOW",
          "privilegesRequired": "HIGH",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 3.4,
        "exploitabilityScore": 1.2
      }
    ]
  },
  "affected": [
    {
      "source": "cna@sap.com",
      "affectedData": [
        {
          "vendor": "SAP",
          "product": "SAP NetWeaver Knowledge Management Configuration Service",
          "versions": [
            {
              "status": "affected",
              "version": "EPBC and EPBC2 from 7.00 to 7.02; KMC-BC 7.30, 7.31, 7.40 and 7.50"
            }
          ]
        }
      ]
    }
  ],
  "published": "2017-12-12T14:29:00.187",
  "references": [
    {
      "url": "http://www.securityfocus.com/bid/102149",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "cna@sap.com"
    },
    {
      "url": "https://blogs.sap.com/2017/12/12/sap-security-patch-day-december-2017/",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cna@sap.com"
    },
    {
      "url": "https://launchpad.support.sap.com/#/notes/2457562",
      "tags": [
        "Permissions Required"
      ],
      "source": "cna@sap.com"
    },
    {
      "url": "http://www.securityfocus.com/bid/102149",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://blogs.sap.com/2017/12/12/sap-security-patch-day-december-2017/",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://launchpad.support.sap.com/#/notes/2457562",
      "tags": [
        "Permissions Required"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-918"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Server Side Request Forgery (SSRF) vulnerability in SAP NetWeaver Knowledge Management Configuration Service, EPBC and EPBC2 from 7.00 to 7.02; KMC-BC 7.30, 7.31, 7.40 and 7.50, that allows an attacker to manipulate the vulnerable application to send crafted requests on behalf of the application."
    },
    {
      "lang": "es",
      "value": "Vulnerabilidad de Server Side Request Forgery (SSRF) en SAP NetWeaver Knowledge Management Configuration Service, EPBC y EPBC2 desde la versión 7.00 hasta la 7.02 y KMC-BC 7.30, 7.31, 7.40 y 7.50, que permite que un atacante manipule la aplicación vulnerable para que envíe peticiones manipuladas en nombre de la aplicación."
    }
  ],
  "lastModified": "2026-06-17T01:09:39.647",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:sap:netweaver_knowledge_management_configuration_service:-:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "675BFE11-5E88-402C-863D-71F7A879201A"
            }
          ],
          "operator": "OR"
        }
      ]
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:sap:epbc:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D9D3A6EA-0E15-4F33-B281-664837B68166",
              "versionEndIncluding": "7.02",
              "versionStartIncluding": "7.00"
            },
            {
              "criteria": "cpe:2.3:a:sap:epbc2:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C13F5F2E-3908-4D44-9947-0E66F02ACB3F",
              "versionEndIncluding": "7.02",
              "versionStartIncluding": "7.00"
            }
          ],
          "operator": "OR"
        }
      ]
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:sap:kmc-bc:7.30:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "37EE16A4-4E4F-4670-A66D-C83091B622CD"
            },
            {
              "criteria": "cpe:2.3:a:sap:kmc-bc:7.31:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F9ECC26B-B53B-431F-85A2-BD85A7CC6DE6"
            },
            {
              "criteria": "cpe:2.3:a:sap:kmc-bc:7.40:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "429F149B-7BF5-4D71-8B60-4D2AB70B5424"
            },
            {
              "criteria": "cpe:2.3:a:sap:kmc-bc:7.50:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4F7AE82C-77F9-4DB8-8DA0-92FD6A1A4F0D"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cna@sap.com"
}