CVE-2023-31404

Under certain conditions, SAP BusinessObjects Business Intelligence Platform (Central Management Service) - versions 420, 430, allows an attacker to access information which would otherwise be restricted. Some users with specific privileges could have access to credentials of other users. It could let them access data sources which would otherwise be restricted.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:sap:businessobjects_business_intelligence:420:*:*:*:*:*:*:*
cpe:2.3:a:sap:businessobjects_business_intelligence:430:*:*:*:*:*:*:*

History

No history.

Information

Published : 2023-05-09 02:15

Updated : 2024-02-28 20:13


NVD link : CVE-2023-31404

Mitre link : CVE-2023-31404

CVE.ORG link : CVE-2023-31404


JSON object : View

Products Affected

sap

  • businessobjects_business_intelligence
CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor