CVE-2014-8309

Severity
5.0MEDIUM
EPSS
0.5%
top 34.43%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 16
Latest updateMay 14

Description

SAP BusinessObjects 4.0 and BusinessObjects XI (BOXI) R2 and 3.1 generates error messages for a failed logon attempt with different time delays depending on whether the user account exists, which allows remote attackers to enumerate valid usernames via SecEnterprise authentication requests to the Session web service.

CVSS vector

AV:N/AC:L/C:P/I:N/A:NExploitability: 10.0 | Impact: 2.9

Affected Packages2 packages

🔴Vulnerability Details

2
GHSA
GHSA-q44j-435f-vxcg: SAP BusinessObjects 42022-05-14
CVEList
CVE-2014-8309: SAP BusinessObjects 42014-10-16