CVE-2023-28764

SAP BusinessObjects Platform - versions 420, 430, Information design tool transmits sensitive information as cleartext in the binaries over the network. This could allow an unauthenticated attacker with deep knowledge to gain sensitive information such as user credentials and domain names, which may have a low impact on confidentiality and no impact on the integrity and availability of the system.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:sap:businessobjects:4.20:*:*:*:*:*:*:*
cpe:2.3:a:sap:businessobjects:4.30:*:*:*:*:*:*:*

History

12 May 2023, 20:44

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.9
CPE cpe:2.3:a:sap:businessobjects:4.30:*:*:*:*:*:*:*
cpe:2.3:a:sap:businessobjects:4.20:*:*:*:*:*:*:*
References (MISC) https://i7p.wdf.sap.corp/sap/support/notes/3302595 - (MISC) https://i7p.wdf.sap.corp/sap/support/notes/3302595 - Broken Link
References (MISC) https://www.sap.com/documents/2022/02/fa865ea4-167e-0010-bca6-c68f7e60039b.html - (MISC) https://www.sap.com/documents/2022/02/fa865ea4-167e-0010-bca6-c68f7e60039b.html - Vendor Advisory

09 May 2023, 01:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-05-09 01:15

Updated : 2024-02-04 23:37


NVD link : CVE-2023-28764

Mitre link : CVE-2023-28764

CVE.ORG link : CVE-2023-28764


JSON object : View

Products Affected

sap

  • businessobjects
CWE
CWE-522

Insufficiently Protected Credentials