CVE-2023-36917

CWE-3073 documents3 sources
Severity
7.5HIGH
EPSS
0.1%
top 76.31%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 11

Description

SAP BusinessObjects Business Intelligence Platform - version 420, 430, allows an unauthorized attacker who had hijacked a user session, to be able to bypass the victim’s old password via brute force, due to unrestricted rate limit for password change functionality. Although the attack has no impact on integrity loss or system availability, this could lead to an attacker to completely takeover a victim’s account.

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 2.2 | Impact: 3.6

Affected Packages2 packages

🔴Vulnerability Details

2
CVEList
Password Change rate limit bypass in SAP BusinessObjects Business Intelligence Platform2023-07-11
GHSA
GHSA-4m3h-hm42-fpq8: SAP BusinessObjects Business Intelligence Platform - version 420, 430, allows an unauthorized attacker who had hijacked a user session, to be able to2023-07-11
CVE-2023-36917 (HIGH CVSS 7.5) | SAP BusinessObjects Business Intell | cvebase.io