CVE-2022-47894

MEDIUM

Apache Zeppelin SAP 0.8.0-0.10.1 - Improper Input Validation

Title source: llm
STIX 2.1

Description

Improper Input Validation vulnerability in Apache Zeppelin SAP.This issue affects Apache Zeppelin SAP: from 0.8.0 before 0.11.0. As this project is retired, we do not plan to release a version that fixes this issue. Users are recommended to find an alternative or restrict access to the instance to trusted users. For more information, the fix already was merged in the source code but Zeppelin decided to retire the SAP component NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

References (3)

Core 3

Scores

CVSS v3 5.3
EPSS 0.0028
EPSS Percentile 51.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-20
Status published
Products (2)
apache/zeppelin 0.8.0 - 0.11.0
org.apache.zeppelin/sap 0.8.0 - 0.11.0Maven
Published Apr 09, 2024
Tracked Since Feb 18, 2026