CVE-2021-40497

SAP BusinessObjects Analysis (edition for OLAP) - versions 420, 430, allows an attacker to exploit certain application endpoints to read sensitive data. These endpoints are normally exposed over the network and successful exploitation could lead to exposure of some system specific data like its version.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:sap:businessobjects_analysis:420:*:*:*:*:*:*:*
cpe:2.3:a:sap:businessobjects_analysis:430:*:*:*:*:*:*:*

History

18 Oct 2021, 21:05

Type Values Removed Values Added
CPE cpe:2.3:a:sap:businessobjects_analysis:420:*:*:*:*:*:*:*
cpe:2.3:a:sap:businessobjects_analysis:430:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : 5.0
v3 : 5.3
References (MISC) https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=587169983 - (MISC) https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=587169983 - Vendor Advisory
References (MISC) https://launchpad.support.sap.com/#/notes/3098917 - (MISC) https://launchpad.support.sap.com/#/notes/3098917 - Permissions Required
CWE CWE-668

12 Oct 2021, 15:17

Type Values Removed Values Added
New CVE

Information

Published : 2021-10-12 15:15

Updated : 2023-12-10 14:09


NVD link : CVE-2021-40497

Mitre link : CVE-2021-40497

CVE.ORG link : CVE-2021-40497


JSON object : View

Products Affected

sap

  • businessobjects_analysis
CWE
CWE-668

Exposure of Resource to Wrong Sphere