CVE-2017-16678
Last modified
CVE-2017-16678 is a vulnerability of currently unknown severity. Server Side Request Forgery (SSRF) vulnerability in SAP NetWeaver Knowledge Management Configuration Service, EPBC and EPBC2 from 7.00 to 7.02; KMC-BC 7.30, 7.31, 7.40 and 7.50, that allows an attacker to manipulate the vulnerable application to send crafted requests on behalf of the application.. EPSS estimates a 0.87% chance of exploitation in the next 30 days.
Description
Server Side Request Forgery (SSRF) vulnerability in SAP NetWeaver Knowledge Management Configuration Service, EPBC and EPBC2 from 7.00 to 7.02; KMC-BC 7.30, 7.31, 7.40 and 7.50, that allows an attacker to manipulate the vulnerable application to send crafted requests on behalf of the application.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Sap | Netweaver Knowledge Management Configuration Service | All versions |
| Sap | Epbc | >= 7.00, <= 7.02 |
| Sap | Epbc2 | >= 7.00, <= 7.02 |
| Sap | Kmc-Bc | 7.30 |
| Sap | Kmc-Bc | 7.31 |
| Sap | Kmc-Bc | 7.40 |
| Sap | Kmc-Bc | 7.50 |
References
- http://www.securityfocus.com/bid/102149Third Party Advisory, VDB Entry
- https://launchpad.support.sap.com/#/notes/2457562Permissions Required
- http://www.securityfocus.com/bid/102149Third Party Advisory, VDB Entry
- https://launchpad.support.sap.com/#/notes/2457562Permissions Required
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2017-16678?
How severe is CVE-2017-16678?
How do I fix CVE-2017-16678?
How Strix Helps
- One Click Account Takeover in GranolaHow a notification link broke out of Electron and led to a one-click account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2017
- CVE-2017-16669coders/wpg.c in GraphicsMagick 1.3.26 allows remote attacker…
- CVE-2017-16670The project import functionality in SoapUI 5.3.0 allows remo…
- CVE-2017-16671A Buffer Overflow issue was discovered in Asterisk Open Sour…
- CVE-2017-16672An issue was discovered in Asterisk Open Source 13 before 13…
- CVE-2017-16673Datto Backup Agent 1.0.6.0 and earlier does not authenticate…
- CVE-2017-16674Datto Windows Agent allows unauthenticated remote command ex…
- CVE-2017-16679URL redirection vulnerability in SAP's Startup Service, SAP …
- CVE-2017-1668IBM Tivoli Key Lifecycle Manager 2.5, 2.6, and 2.7 could all…
- CVE-2017-16680Two potential audit log injections in SAP HANA extended appl…
- CVE-2017-16681Cross-Site Scripting (XSS) vulnerability in SAP Business Int…
- CVE-2017-16682SAP NetWeaver Internet Transaction Server (ITS), SAP Basis f…
- CVE-2017-16683Denial of Service (DOS) in SAP Business Objects Platform, En…
Are you affected by CVE-2017-16678?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
