CVE-2023-31404

Severity
5.0MEDIUM
EPSS
0.3%
top 50.94%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 9
Latest updateJul 6

Description

Under certain conditions, SAP BusinessObjects Business Intelligence Platform (Central Management Service) - versions 420, 430, allows an attacker to access information which would otherwise be restricted. Some users with specific privileges could have access to credentials of other users. It could let them access data sources which would otherwise be restricted.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:NExploitability: 3.1 | Impact: 1.4

🔴Vulnerability Details

2
GHSA
GHSA-38rw-rq2q-vfhr: Under certain conditions, SAP BusinessObjects Business Intelligence Platform (Central Management Service) - versions 420, 430, allows an attacker to a2023-07-06
CVEList
Information Disclosure in SAP BusinessObjects Business Intelligence Platform (Central Management Service)2023-05-09