Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-gh99-56qc-35cc

Опубликовано: 08 авг. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 4.4

Описание

In SAP BusinessObjects Business Intelligence - version 420, If a user logs in to a particular program, under certain specific conditions memory might not be cleared up properly, due to which attacker might be able to get access to user credentials. For a successful attack, the attacker needs to have local access to the system. There is no impact on availability and integrity.

In SAP BusinessObjects Business Intelligence - version 420, If a user logs in to a particular program, under certain specific conditions memory might not be cleared up properly, due to which attacker might be able to get access to user credentials. For a successful attack, the attacker needs to have local access to the system. There is no impact on availability and integrity.

EPSS

Процентиль: 9%
0.00031
Низкий

4.4 Medium

CVSS3

Дефекты

CWE-200
CWE-312

Связанные уязвимости

CVSS3: 4.4
nvd
больше 2 лет назад

In SAP BusinessObjects Business Intelligence - version 420, If a user logs in to a particular program, under certain specific conditions memory might not be cleared up properly, due to which attacker might be able to get access to user credentials. For a successful attack, the attacker needs to have local access to the system. There is no impact on availability and integrity.

CVSS3: 4.4
fstec
больше 2 лет назад

Уязвимость платформы бизнес-аналитики SAP BusinessObjects Business Intelligence, связанная с недостаточной защитой служебных данных, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

EPSS

Процентиль: 9%
0.00031
Низкий

4.4 Medium

CVSS3

Дефекты

CWE-200
CWE-312