CVE-2014-9320Improper Authentication in SAP Businessobjects Edge

Severity
9.8CRITICALNVD
EPSS
9.5%
top 7.16%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedAug 9
Latest updateMay 17

Description

SAP BusinessObjects Edge 4.1 allows remote attackers to obtain the SI_PLATFORM_SEARCH_SERVER_LOGON_TOKEN token and consequently gain SYSTEM privileges via vectors involving CORBA calls, aka SAP Note 2039905.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages1 packages

Patches

🔴Vulnerability Details

2
GHSA
GHSA-hxxq-wv4r-w3gr: SAP BusinessObjects Edge 42022-05-17
CVEList
CVE-2014-9320: SAP BusinessObjects Edge 42021-08-09
CVE-2014-9320 — Improper Authentication in SAP | cvebase