Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-5jjr-9ghm-5r56

Опубликовано: 11 авг. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 8.2

Описание

SAP BusinessObjects Business Intelligence Platform (Open Document) - versions 430, 430, allows an unauthenticated attacker to retrieve sensitive information plain text over the network. On successful exploitation, the attacker can view any data available for a business user and put load on the application by an automated attack. Thus, completely compromising confidentiality but causing a limited impact on the availability of the application.

SAP BusinessObjects Business Intelligence Platform (Open Document) - versions 430, 430, allows an unauthenticated attacker to retrieve sensitive information plain text over the network. On successful exploitation, the attacker can view any data available for a business user and put load on the application by an automated attack. Thus, completely compromising confidentiality but causing a limited impact on the availability of the application.

EPSS

Процентиль: 69%
0.00603
Низкий

8.2 High

CVSS3

Дефекты

CWE-319

Связанные уязвимости

CVSS3: 8.2
nvd
больше 3 лет назад

SAP BusinessObjects Business Intelligence Platform (Open Document) - versions 420, 430, allows an unauthenticated attacker to retrieve sensitive information plain text over the network. On successful exploitation, the attacker can view any data available for a business user and put load on the application by an automated attack. Thus, completely compromising confidentiality but causing a limited impact on the availability of the application.

CVSS3: 7.5
fstec
больше 3 лет назад

Уязвимость платформы бизнес-аналитики SAP BusinessObjects Business Intelligence, связанная с раскрытием информации, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

EPSS

Процентиль: 69%
0.00603
Низкий

8.2 High

CVSS3

Дефекты

CWE-319