CVE-2023-28765

An attacker with basic privileges in SAP BusinessObjects Business Intelligence Platform (Promotion Management) - versions 420, 430, can get access to lcmbiar file and further decrypt the file. After this attacker can gain access to BI user’s passwords and depending on the privileges of the BI user, the attacker can perform operations that can completely compromise the application.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:sap:businessobjects_business_intelligence:420:*:*:*:*:*:*:*
cpe:2.3:a:sap:businessobjects_business_intelligence:430:*:*:*:*:*:*:*

History

14 Apr 2023, 19:49

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8
CWE CWE-200 NVD-CWE-noinfo
First Time Sap
Sap businessobjects Business Intelligence
CPE cpe:2.3:a:sap:businessobjects_business_intelligence:420:*:*:*:*:*:*:*
cpe:2.3:a:sap:businessobjects_business_intelligence:430:*:*:*:*:*:*:*
References (MISC) https://launchpad.support.sap.com/#/notes/3298961 - (MISC) https://launchpad.support.sap.com/#/notes/3298961 - Permissions Required
References (MISC) https://www.sap.com/documents/2022/02/fa865ea4-167e-0010-bca6-c68f7e60039b.html - (MISC) https://www.sap.com/documents/2022/02/fa865ea4-167e-0010-bca6-c68f7e60039b.html - Vendor Advisory

11 Apr 2023, 03:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-04-11 03:15

Updated : 2023-12-10 15:01


NVD link : CVE-2023-28765

Mitre link : CVE-2023-28765

CVE.ORG link : CVE-2023-28765


JSON object : View

Products Affected

sap

  • businessobjects_business_intelligence
CWE
NVD-CWE-noinfo CWE-200

Exposure of Sensitive Information to an Unauthorized Actor