Under certain conditions, SAP BusinessObjects Business Intelligence Platform (Central Management Service) - versions 420, 430, allows an attacker to access information which would otherwise be restricted. Some users with specific privileges could have access to credentials of other users. It could let them access data sources which would otherwise be restricted.
References
Link | Resource |
---|---|
https://launchpad.support.sap.com/#/notes/3038911 | Permissions Required Vendor Advisory |
https://www.sap.com/documents/2022/02/fa865ea4-167e-0010-bca6-c68f7e60039b.html | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2023-05-09 02:15
Updated : 2024-02-28 20:13
NVD link : CVE-2023-31404
Mitre link : CVE-2023-31404
CVE.ORG link : CVE-2023-31404
JSON object : View
Products Affected
sap
- businessobjects_business_intelligence
CWE
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor