In SAP BusinessObjects Business Intelligence
Platform, if Single Signed On is enabled on Enterprise authentication, an
unauthorized user can get a logon token using a REST endpoint. The attacker can
fully compromise the system resulting in High impact on confidentiality,
integrity and availability.
Metrics
Affected Vendors & Products
References
History
Thu, 12 Sep 2024 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Sap
Sap business Objects Business Intelligence Platform |
|
| CPEs | cpe:2.3:a:sap:business_objects_business_intelligence_platform:enterprise_430:*:*:*:*:*:*:* cpe:2.3:a:sap:business_objects_business_intelligence_platform:enterprise_440:*:*:*:*:*:*:* |
|
| Vendors & Products |
Sap
Sap business Objects Business Intelligence Platform |
Tue, 13 Aug 2024 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Sap Se
Sap Se sap Business Objects Business Intgelligence Platform |
|
| CPEs | cpe:2.3:a:sap_se:sap_business_objects_business_intgelligence_platform:430:*:*:*:*:*:*:* cpe:2.3:a:sap_se:sap_business_objects_business_intgelligence_platform:440:*:*:*:*:*:*:* |
|
| Vendors & Products |
Sap Se
Sap Se sap Business Objects Business Intgelligence Platform |
|
| Metrics |
ssvc
|
Tue, 13 Aug 2024 03:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In SAP BusinessObjects Business Intelligence Platform, if Single Signed On is enabled on Enterprise authentication, an unauthorized user can get a logon token using a REST endpoint. The attacker can fully compromise the system resulting in High impact on confidentiality, integrity and availability. | |
| Title | Missing Authentication check in SAP BusinessObjects Business Intelligence Platform | |
| Weaknesses | CWE-862 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: sap
Published: 2024-08-13T03:31:37.327Z
Updated: 2024-08-16T04:01:44.403Z
Reserved: 2024-07-22T08:06:52.675Z
Link: CVE-2024-41730
Updated: 2024-08-13T13:58:07.002Z
Status : Analyzed
Published: 2024-08-13T04:15:08.050
Modified: 2024-09-12T13:56:51.237
Link: CVE-2024-41730
No data.