CVE-2022-27671Sensitive Info Insertion into Sent Data in SE SAP Businessobjects Business Intelligence Platform

Severity
6.5MEDIUMNVD
EPSS
1.0%
top 23.28%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 12
Latest updateApr 13

Description

A CSRF token visible in the URL may possibly lead to information disclosure vulnerability.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:NExploitability: 2.8 | Impact: 3.6

🔴Vulnerability Details

2
GHSA
GHSA-qjv9-cq4h-7c4j: A CSRF token visible in the URL may possibly lead to information disclosure vulnerability2022-04-13
CVEList
CVE-2022-27671: A CSRF token visible in the URL may possibly lead to information disclosure vulnerability2022-04-12
CVE-2022-27671 — MEDIUM severity | cvebase