CVE-2023-31404

Under certain conditions, SAP BusinessObjects Business Intelligence Platform (Central Management Service) - versions 420, 430, allows an attacker to access information which would otherwise be restricted. Some users with specific privileges could have access to credentials of other users. It could let them access data sources which would otherwise be restricted.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:sap:businessobjects_business_intelligence:420:*:*:*:*:*:*:*
cpe:2.3:a:sap:businessobjects_business_intelligence:430:*:*:*:*:*:*:*

History

15 May 2023, 17:32

Type Values Removed Values Added
CPE cpe:2.3:a:sap:businessobjects_business_intelligence:430:*:*:*:*:*:*:*
cpe:2.3:a:sap:businessobjects_business_intelligence:420:*:*:*:*:*:*:*
First Time Sap
Sap businessobjects Business Intelligence
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.0
References (MISC) https://www.sap.com/documents/2022/02/fa865ea4-167e-0010-bca6-c68f7e60039b.html - (MISC) https://www.sap.com/documents/2022/02/fa865ea4-167e-0010-bca6-c68f7e60039b.html - Vendor Advisory
References (MISC) https://launchpad.support.sap.com/#/notes/3038911 - (MISC) https://launchpad.support.sap.com/#/notes/3038911 - Permissions Required, Vendor Advisory

09 May 2023, 02:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-05-09 02:15

Updated : 2023-12-10 15:01


NVD link : CVE-2023-31404

Mitre link : CVE-2023-31404

CVE.ORG link : CVE-2023-31404


JSON object : View

Products Affected

sap

  • businessobjects_business_intelligence
CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor