Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-p36f-hqc8-f7jr

Опубликовано: 13 июл. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 8.8

Описание

SAP BusinessObjects CMC allows an unauthenticated attacker to retrieve token information over the network which would otherwise be restricted. This can be achieved only when a legitimate user accesses the application and a local compromise occurs, like sniffing or social engineering. On successful exploitation, the attacker can completely compromise the application.

SAP BusinessObjects CMC allows an unauthenticated attacker to retrieve token information over the network which would otherwise be restricted. This can be achieved only when a legitimate user accesses the application and a local compromise occurs, like sniffing or social engineering. On successful exploitation, the attacker can completely compromise the application.

EPSS

Процентиль: 40%
0.00182
Низкий

8.8 High

CVSS3

Дефекты

CWE-352

Связанные уязвимости

CVSS3: 8.8
nvd
больше 3 лет назад

SAP BusinessObjects CMC allows an unauthenticated attacker to retrieve token information over the network which would otherwise be restricted. This can be achieved only when a legitimate user accesses the application and a local compromise occurs, like sniffing or social engineering. On successful exploitation, the attacker can completely compromise the application.

CVSS3: 8.8
fstec
больше 3 лет назад

Уязвимость компонента Central Management Console (CMC) платформы бизнес-аналитики SAP BusinessObjects Business Intelligence, позволяющая нарушителю раскрыть защищаемую информацию или вызвать отказ в обслуживании

EPSS

Процентиль: 40%
0.00182
Низкий

8.8 High

CVSS3

Дефекты

CWE-352