CVE-2022-22541Exposure of Sensitive Information Due to Incompatible Policies in SE SAP Businessobjects Business Intelligence Platform

Severity
6.5MEDIUMNVD
EPSS
0.3%
top 48.09%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 12
Latest updateApr 13

Description

SAP BusinessObjects Business Intelligence Platform - versions 420, 430, may allow legitimate users to access information they shouldn't see through relational or OLAP connections. The main impact is the disclosure of company data to people that shouldn't or don't need to have access.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NExploitability: 2.8 | Impact: 3.6

🔴Vulnerability Details

2
GHSA
GHSA-fjm9-j6wv-mc7w: SAP BusinessObjects Business Intelligence Platform - versions 420, 430, may allow legitimate users to access information they shouldn't see through re2022-04-13
CVEList
CVE-2022-22541: SAP BusinessObjects Business Intelligence Platform - versions 420, 430, may allow legitimate users to access information they shouldn't see through re2022-04-12
CVE-2022-22541 — MEDIUM severity | cvebase