CVE-2024-41730

Aug. 13, 2024, 12:58 p.m.

Undergoing Analysis
CVE has been recently published to the CVE List and has been received by the NVD.

Products

SAP BusinessObjects Business Intelligence Platform

Source

cna@sap.com

Tags

CVE-2024-41730 details

Published : Aug. 13, 2024, 4:15 a.m.
Last Modified : Aug. 13, 2024, 12:58 p.m.

Description

In SAP BusinessObjects Business Intelligence Platform, if Single Signed On is enabled on Enterprise authentication, an unauthorized user can get a logon token using a REST endpoint. The attacker can fully compromise the system resulting in High impact on confidentiality, integrity and availability.

CVSS Score

1 2 3 4 5 6 7 8 9.8 10

Weakness

Weakness Name Description
CWE-862 Missing Authorization The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

CVSS Data

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

Base Score

9.8

Exploitability Score

3.9

Impact Score

5.9

Base Severity

CRITICAL

References

URL Source
https://me.sap.com/notes/3479478 cna@sap.com
https://url.sap/sapsecuritypatchday cna@sap.com
This website uses the NVD API, but is not approved or certified by it.