Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-fg4w-vj95-g2c7

Опубликовано: 13 авг. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

In SAP BusinessObjects Business Intelligence Platform, if Single Signed On is enabled on Enterprise authentication, an unauthorized user can get a logon token using a REST endpoint. The attacker can fully compromise the system resulting in High impact on confidentiality, integrity and availability.

In SAP BusinessObjects Business Intelligence Platform, if Single Signed On is enabled on Enterprise authentication, an unauthorized user can get a logon token using a REST endpoint. The attacker can fully compromise the system resulting in High impact on confidentiality, integrity and availability.

EPSS

Процентиль: 95%
0.19511
Средний

9.8 Critical

CVSS3

Дефекты

CWE-862

Связанные уязвимости

CVSS3: 9.8
nvd
больше 1 года назад

In SAP BusinessObjects Business Intelligence Platform, if Single Signed On is enabled on Enterprise authentication, an unauthorized user can get a logon token using a REST endpoint. The attacker can fully compromise the system resulting in High impact on confidentiality, integrity and availability.

CVSS3: 9.8
fstec
больше 1 года назад

Уязвимость функционала единого входа (SSO) платформы бизнес-аналитики SAP BusinessObjects Business Intelligence, позволяющая нарушителю получить полный доступ к устройству

EPSS

Процентиль: 95%
0.19511
Средний

9.8 Critical

CVSS3

Дефекты

CWE-862