Under certain conditions, SAP BusinessObjects Business Intelligence Platform (Central Management Service) - versions 420, 430, allows an attacker to access information which would otherwise be restricted. Some users with specific privileges could have access to credentials of other users. It could let them access data sources which would otherwise be restricted.
References
Link | Resource |
---|---|
https://launchpad.support.sap.com/#/notes/3038911 | Permissions Required Vendor Advisory |
https://www.sap.com/documents/2022/02/fa865ea4-167e-0010-bca6-c68f7e60039b.html | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
15 May 2023, 17:32
Type | Values Removed | Values Added |
---|---|---|
References | (MISC) https://www.sap.com/documents/2022/02/fa865ea4-167e-0010-bca6-c68f7e60039b.html - Vendor Advisory | |
References | (MISC) https://launchpad.support.sap.com/#/notes/3038911 - Permissions Required, Vendor Advisory | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 5.0 |
CPE | cpe:2.3:a:sap:businessobjects_business_intelligence:420:*:*:*:*:*:*:* cpe:2.3:a:sap:businessobjects_business_intelligence:430:*:*:*:*:*:*:* |
09 May 2023, 02:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2023-05-09 02:15
Updated : 2024-02-04 23:37
NVD link : CVE-2023-31404
Mitre link : CVE-2023-31404
CVE.ORG link : CVE-2023-31404
JSON object : View
Products Affected
sap
- businessobjects_business_intelligence
CWE
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor