Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-9qf4-6p5h-r4f5

Опубликовано: 09 дек. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 5.4

Описание

SAP BusinessObjects Business Intelligence Platform lets an unauthenticated remote attacker send crafted requests through the URL parameter that controls the login page error message. This can cause the server to fetch attacker-supplied URLs, resulting in low impact to confidentiality and integrity, and no impact to availability.

SAP BusinessObjects Business Intelligence Platform lets an unauthenticated remote attacker send crafted requests through the URL parameter that controls the login page error message. This can cause the server to fetch attacker-supplied URLs, resulting in low impact to confidentiality and integrity, and no impact to availability.

EPSS

Процентиль: 9%
0.00034
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-116

Связанные уязвимости

CVSS3: 5.4
nvd
2 месяца назад

SAP BusinessObjects Business Intelligence Platform lets an unauthenticated remote attacker send crafted requests through the URL parameter that controls the login page error message. This can cause the server to fetch attacker-supplied URLs, resulting in low impact to confidentiality and integrity, and no impact to availability.

CVSS3: 5.4
fstec
2 месяца назад

Уязвимость платформы бизнес-аналитики SAP BusinessObjects Business Intelligence, связанная с неправильным кодированием или экранированием выходных данных, позволяющая нарушителю осуществить SSRF-атаку

EPSS

Процентиль: 9%
0.00034
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-116