CVE-2024-41730

In SAP BusinessObjects Business Intelligence Platform, if Single Signed On is enabled on Enterprise authentication, an unauthorized user can get a logon token using a REST endpoint. The attacker can fully compromise the system resulting in High impact on confidentiality, integrity and availability.
References
Link Resource
https://me.sap.com/notes/3479478 Permissions Required
https://url.sap/sapsecuritypatchday Vendor Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:sap:business_objects_business_intelligence_platform:enterprise_430:*:*:*:*:*:*:*
cpe:2.3:a:sap:business_objects_business_intelligence_platform:enterprise_440:*:*:*:*:*:*:*

History

12 Sep 2024, 13:56

Type Values Removed Values Added
First Time Sap
Sap business Objects Business Intelligence Platform
References () https://me.sap.com/notes/3479478 - () https://me.sap.com/notes/3479478 - Permissions Required
References () https://url.sap/sapsecuritypatchday - () https://url.sap/sapsecuritypatchday - Vendor Advisory
CPE cpe:2.3:a:sap:business_objects_business_intelligence_platform:enterprise_440:*:*:*:*:*:*:*
cpe:2.3:a:sap:business_objects_business_intelligence_platform:enterprise_430:*:*:*:*:*:*:*
Summary
  • (es) En la plataforma SAP BusinessObjects Business Intelligence, si el inicio de sesión único está habilitado en la autenticación empresarial, un usuario no autorizado puede obtener un token de inicio de sesión mediante un endpoint REST. El atacante puede comprometer completamente el sistema, lo que tendrá un alto impacto en la confidencialidad, la integridad y la disponibilidad.

13 Aug 2024, 04:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-08-13 04:15

Updated : 2024-09-12 13:56


NVD link : CVE-2024-41730

Mitre link : CVE-2024-41730

CVE.ORG link : CVE-2024-41730


JSON object : View

Products Affected

sap

  • business_objects_business_intelligence_platform
CWE
CWE-862

Missing Authorization