Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-7345-wwch-f7q7

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

In some situations, when a client cancels a query in SAP BusinessObjects Business Intelligence Platform (Web Intelligence), versions 4.2, 4.3, the attacker can then query and receive the whole data set instead of just what is part of their authorized security profile, resulting in Information Disclosure.

In some situations, when a client cancels a query in SAP BusinessObjects Business Intelligence Platform (Web Intelligence), versions 4.2, 4.3, the attacker can then query and receive the whole data set instead of just what is part of their authorized security profile, resulting in Information Disclosure.

EPSS

Процентиль: 50%
0.0027
Низкий

Связанные уязвимости

CVSS3: 6.5
nvd
больше 6 лет назад

In some situations, when a client cancels a query in SAP BusinessObjects Business Intelligence Platform (Web Intelligence), versions 4.2, 4.3, the attacker can then query and receive the whole data set instead of just what is part of their authorized security profile, resulting in Information Disclosure.

CVSS3: 6.5
fstec
больше 6 лет назад

Уязвимость компонента Web Intelligence платформы бизнес-аналитики SAP BusinessObjects Business Intelligence, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

EPSS

Процентиль: 50%
0.0027
Низкий