CVE-2023-31404
Last modified
CVE-2023-31404 is a medium-severity vulnerability rated 5/10 on the CVSS scale. Under certain conditions, SAP BusinessObjects Business Intelligence Platform (Central Management Service) - versions 420, 430, allows an attacker to access information which would otherwise be restricted. Some users with specific privileges could have access to credentials of other users. EPSS estimates a 0.47% chance of exploitation in the next 30 days.
Description
Under certain conditions, SAP BusinessObjects Business Intelligence Platform (Central Management Service) - versions 420, 430, allows an attacker to access information which would otherwise be restricted. Some users with specific privileges could have access to credentials of other users. It could let them access data sources which would otherwise be restricted.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Sap | Businessobjects Business Intelligence | 420 |
| Sap | Businessobjects Business Intelligence | 430 |
References
- https://launchpad.support.sap.com/#/notes/3038911Permissions Required, Vendor Advisory
- https://launchpad.support.sap.com/#/notes/3038911Permissions Required, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2023-31404?
How severe is CVE-2023-31404?
How do I fix CVE-2023-31404?
Are you affected by CVE-2023-31404?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
