CVE-2023-0020
published 2023-02-14CVE-2023-0020: SAP BusinessObjects Business Intelligence platform - versions 420, 430, allows an authenticated attacker to access sensitive information which is otherwise…
PriorityP337high7.1CVSS 3.1
AVNACLPRLUINSUCHILAN
EPSS
0.52%
40.7th percentile
SAP BusinessObjects Business Intelligence platform - versions 420, 430, allows an authenticated attacker to access sensitive information which is otherwise restricted. On successful exploitation, there could be a high impact on confidentiality and limited impact on integrity of the application.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| sap | businessobjects_business_intelligence_platform | — | — |
| sap | businessobjects_business_intelligence_platform | — | — |
| sap_se | sap_businessobjects_business_intelligence_platform | — | — |
| sap_se | sap_businessobjects_business_intelligence_platform | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-hjg7-v455-hqpc: SAP BusinessObjects Business Intelligence platform - versions 420, 430, allows an authenticated attacker to access sensitive information which is othe
ghsa_unreviewed·2023-02-14
CVE-2023-0020 [HIGH] CWE-200 GHSA-hjg7-v455-hqpc: SAP BusinessObjects Business Intelligence platform - versions 420, 430, allows an authenticated attacker to access sensitive information which is othe
SAP BusinessObjects Business Intelligence platform - versions 420, 430, allows an authenticated attacker to access sensitive information which is otherwise restricted. On successful exploitation, there could be a high impact on confidentiality and limited impact on integrity of the application.
VMware
VMware Aria Operations updates address local privilege escalation vulnerability. (CVE-2023-34043)
vendor_vmware·2023-09-26·CVSS 6.7
CVE-2023-34043 [MEDIUM] VMware Aria Operations updates address local privilege escalation vulnerability. (CVE-2023-34043)
VMSA-2023-0020: VMware Aria Operations updates address local privilege escalation vulnerability. (CVE-2023-34043)
VMware Aria Operations contains a local privilege escalation vulnerability. VMware has evaluated the severity of this issue to be in the Moderate Severity Range with a maximum CVSSv3 base score of 6.7.
CVEs: CVE-2023-34043
Affected products: VMware Aria, VMware Cloud Foundation
No detection rules found.
No public exploits indexed.
2023-02-14
Published