Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-h2xx-fx3f-hj9x

Опубликовано: 11 мар. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 4.1

Описание

Due to improper error handling in SAP Business Objects Business Intelligence Platform, technical details of the application are revealed in exceptions thrown to the user and in stack traces. Only an attacker with administrator level privileges has access to this disclosed information, and they could use it to craft further exploits. There is no impact on the integrity and availability of the application.

Due to improper error handling in SAP Business Objects Business Intelligence Platform, technical details of the application are revealed in exceptions thrown to the user and in stack traces. Only an attacker with administrator level privileges has access to this disclosed information, and they could use it to craft further exploits. There is no impact on the integrity and availability of the application.

EPSS

Процентиль: 31%
0.00117
Низкий

4.1 Medium

CVSS3

Дефекты

CWE-209

Связанные уязвимости

CVSS3: 4.1
nvd
11 месяцев назад

Due to improper error handling in SAP Business Objects Business Intelligence Platform, technical details of the application are revealed in exceptions thrown to the user and in stack traces. Only an attacker with administrator level privileges has access to this disclosed information, and they could use it to craft further exploits. There is no impact on the integrity and availability of the application.

CVSS3: 4.1
fstec
11 месяцев назад

Уязвимость платформы бизнес-аналитики SAP BusinessObjects Business Intelligence Platform, связанная с недостатками механизма формирования отчетов об ошибках, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

EPSS

Процентиль: 31%
0.00117
Низкий

4.1 Medium

CVSS3

Дефекты

CWE-209