Impact
The vulnerability is a Server‑Side Request Forgery in SAP Manufacturing Integration and Intelligence that allows an attacker to force the server to initiate arbitrary outbound requests. If those requests are processed by the application and combined with XML/XSL processing, the attacker could execute scripts on the server, potentially compromising the confidentiality, integrity, and availability of the application, though the impact is described as low.
Affected Systems
Affected systems are any deployed instances of SAP Manufacturing Integration and Intelligence. No specific versions are listed, so all current releases may be impacted.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity. EPSS is not available, so the likelihood of exploitation cannot be quantified. The vulnerability is not listed in the CISA KEV catalog, indicating no confirmed large‑scale exploitation yet. The likely attack vector is a remote attacker sending crafted requests to the vulnerable server, exploiting the SSRF flaw and any XML/XSLT processing that could allow script execution. The moderate CVSS score and lack of KEV status still warrant timely remediation.
OpenCVE Enrichment