Back to overview

CVE-2023-40622

CRITICAL
9.9
CVSS 3.1
Description
SAP BusinessObjects Business Intelligence Platform (Promotion Management) - versions 420, 430, under certain condition allows an authenticated attacker to view sensitive information which is otherwise restricted. On successful exploitation, the attacker can completely compromise the application causing high impact on confidentiality, integrity, and availability.

Metadata

CVE ID
CVE-2023-40622
State
PUBLISHED
Assigner
sap
Reserved
2023-08-17 18:10 UTC
Published
2023-09-12 02:03 UTC
Last updated
2024-09-28 22:11 UTC
Primary CWE
CWE-732
CWE-732: Incorrect Permission Assignment for Critical Resour…
Vendor / Product
SAP_SE / SAP BusinessObjects Business Intelligence Platform (Promotion Management)
Sources
cve.org  ·  NVD

Severity & Metrics

9.9 CRITICAL CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
SSVC — CISA Coordinator
Exploitation
none
Automatable
no
Tech. Impact
total
Affected products (1)
VendorProductPlatformVersions
SAP_SE SAP BusinessObjects Business Intelligence Platform (Promotion Management) 420, 430
Weakness (CWE)
CWESourceDescription
CWE-732 cna CWE-732: Incorrect Permission Assignment for Critical Resource
CVSS scores (1)
ScoreSeverityVersionSourceVector
9.9 CRITICAL 3.1 cna CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Back to overview