CVE-2017-16678: SAP Epbc

Medium severity, CVSS 4.7. EPSS: 0.9% chance of exploitation in the next 30 days.

Server Side Request Forgery (SSRF) vulnerability in SAP NetWeaver Knowledge Management Configuration Service, EPBC and EPBC2 from 7.00 to 7.02; KMC-BC 7.30, 7.31, 7.40 and 7.50, that allows an attacker to manipulate the vulnerable application to send crafted requests on behalf of the application.

Affected products

  • SAP Epbc: from 7.00, up to and including 7.02
  • SAP EPBC2: from 7.00, up to and including 7.02
  • SAP Kmc-Bc: version 7.30 only; version 7.31 only; version 7.40 only; version 7.50 only
  • SAP NetWeaver Knowledge Management Configuration Service: affected versions not specified

Published 2017-12-12. Last modified 2026-06-17.