CVE-2022-35296

Under certain conditions, the application SAP BusinessObjects Business Intelligence Platform (Version Management System) exposes sensitive information to an actor over the network with high privileges that is not explicitly authorized to have access to that information, leading to a high impact on Confidentiality.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:sap:businessobjects_business_intelligence:420:*:*:*:*:*:*:*
cpe:2.3:a:sap:businessobjects_business_intelligence:430:*:*:*:*:*:*:*

History

12 Oct 2022, 17:29

Type Values Removed Values Added
First Time Sap businessobjects Business Intelligence
Sap
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 4.9
References (MISC) https://www.sap.com/documents/2022/02/fa865ea4-167e-0010-bca6-c68f7e60039b.html - (MISC) https://www.sap.com/documents/2022/02/fa865ea4-167e-0010-bca6-c68f7e60039b.html - Vendor Advisory
References (MISC) https://launchpad.support.sap.com/#/notes/3233226 - (MISC) https://launchpad.support.sap.com/#/notes/3233226 - Permissions Required, Vendor Advisory
CWE CWE-200
CPE cpe:2.3:a:sap:businessobjects_business_intelligence:430:*:*:*:*:*:*:*
cpe:2.3:a:sap:businessobjects_business_intelligence:420:*:*:*:*:*:*:*

11 Oct 2022, 21:15

Type Values Removed Values Added
New CVE

Information

Published : 2022-10-11 21:15

Updated : 2023-12-10 14:35


NVD link : CVE-2022-35296

Mitre link : CVE-2022-35296

CVE.ORG link : CVE-2022-35296


JSON object : View

Products Affected

sap

  • businessobjects_business_intelligence
CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor