VYPR
Medium severity4.7NVD Advisory· Published Dec 12, 2017· Updated May 13, 2026

CVE-2017-16678

CVE-2017-16678

Description

Server Side Request Forgery (SSRF) vulnerability in SAP NetWeaver Knowledge Management Configuration Service, EPBC and EPBC2 from 7.00 to 7.02; KMC-BC 7.30, 7.31, 7.40 and 7.50, that allows an attacker to manipulate the vulnerable application to send crafted requests on behalf of the application.

Affected products

8
  • cpe:2.3:a:sap:epbc:*:*:*:*:*:*:*:*
    Range: >=7.00,<=7.02
  • cpe:2.3:a:sap:epbc2:*:*:*:*:*:*:*:*
    Range: >=7.00,<=7.02
  • SAP/Kmc Bc4 versions
    cpe:2.3:a:sap:kmc-bc:7.30:*:*:*:*:*:*:*+ 3 more
    • cpe:2.3:a:sap:kmc-bc:7.30:*:*:*:*:*:*:*
    • cpe:2.3:a:sap:kmc-bc:7.31:*:*:*:*:*:*:*
    • cpe:2.3:a:sap:kmc-bc:7.40:*:*:*:*:*:*:*
    • cpe:2.3:a:sap:kmc-bc:7.50:*:*:*:*:*:*:*
  • cpe:2.3:a:sap:netweaver_knowledge_management_configuration_service:-:*:*:*:*:*:*:*
  • SAP/SAP NetWeaver Knowledge Management Configuration Servicev5
    Range: EPBC and EPBC2 from 7.00 to 7.02; KMC-BC 7.30, 7.31, 7.40 and 7.50

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

3

News mentions

0

No linked articles in our index yet.