SAP BusinessObjects Business Intelligence Platform allows a high privilege user to run client desktop applications even if some of the DLLs are not digitally signed or if the signature is broken. The attacker needs to have local access to the vulnerable system to perform DLL related tasks. This could result in a high impact on confidentiality and integrity of the application.
References
| Link | Resource |
|---|---|
| https://me.sap.com/notes/3425287 | Permissions Required |
| https://url.sap/sapsecuritypatchday | Patch |
Configurations
Configuration 1 (hide)
|
History
28 Oct 2025, 18:40
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:sap:businessobjects_business_intelligence_platform:430:*:*:*:-:*:*:* | |
| References | () https://me.sap.com/notes/3425287 - Permissions Required | |
| References | () https://url.sap/sapsecuritypatchday - Patch | |
| First Time |
Sap
Sap businessobjects Business Intelligence Platform |
10 Sep 2024, 12:09
| Type | Values Removed | Values Added |
|---|---|---|
| Summary |
|
10 Sep 2024, 05:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2024-09-10 05:15
Updated : 2025-10-28 18:40
NVD link : CVE-2024-45281
Mitre link : CVE-2024-45281
CVE.ORG link : CVE-2024-45281
JSON object : View
Products Affected
sap
- businessobjects_business_intelligence_platform
CWE
CWE-426
Untrusted Search Path
