CVE-2023-40622
Information Disclosure vulnerability in SAP BusinessObjects Business Intelligence Platform (Promotion Management)
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
SAP BusinessObjects Business Intelligence Platform (Promotion Management) - versions 420, 430, under certain condition allows an authenticated attacker to view sensitive information which is otherwise restricted. On successful exploitation, the attacker can completely compromise the application causing high impact on confidentiality, integrity, and availability.
SAP BusinessObjects Business Intelligence Platform (Promotion Management): las versiones 420, 430, bajo ciertas condiciones, permiten a un atacante autenticado ver información sensible que de otro modo estaría restringida. En una explotación exitosa, el atacante puede comprometer completamente la aplicación causando un alto impacto en la confidencialidad, integridad y disponibilidad.
CVSS Scores
SSVC
- Decision:Track*
Timeline
- 2023-08-17 CVE Reserved
- 2023-09-12 CVE Published
- 2024-09-18 EPSS Updated
- 2024-09-28 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
- CWE-732: Incorrect Permission Assignment for Critical Resource
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://www.sap.com/documents/2022/02/fa865ea4-167e-0010-bca6-c68f7e60039b.html | 2023-09-13 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Sap Search vendor "Sap" | Businessobjects Business Intelligence Search vendor "Sap" for product "Businessobjects Business Intelligence" | 420 Search vendor "Sap" for product "Businessobjects Business Intelligence" and version "420" | - |
Affected
| ||||||
Sap Search vendor "Sap" | Businessobjects Business Intelligence Search vendor "Sap" for product "Businessobjects Business Intelligence" | 430 Search vendor "Sap" for product "Businessobjects Business Intelligence" and version "430" | - |
Affected
|