### [CVE-2017-16678](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-16678) ![](https://img.shields.io/static/v1?label=Product&message=SAP%20NetWeaver%20Knowledge%20Management%20Configuration%20Service&color=blue) ![](https://img.shields.io/static/v1?label=Version&message=EPBC%20and%20EPBC2%20from%207.00%20to%207.02%3B%20KMC-BC%207.30%2C%207.31%2C%207.40%20and%207.50%20&color=brightgreen) ![](https://img.shields.io/static/v1?label=Vulnerability&message=Server%20Side%20Request%20Forgery%20(SSRF)&color=brightgreen) ### Description Server Side Request Forgery (SSRF) vulnerability in SAP NetWeaver Knowledge Management Configuration Service, EPBC and EPBC2 from 7.00 to 7.02; KMC-BC 7.30, 7.31, 7.40 and 7.50, that allows an attacker to manipulate the vulnerable application to send crafted requests on behalf of the application. ### POC #### Reference - https://blogs.sap.com/2017/12/12/sap-security-patch-day-december-2017/ #### Github No PoCs found on GitHub currently.