CVE-2024-34684Sensitive Information Exposure in SE SAP Businessobjects Business Intelligence Platform

Severity
6.0MEDIUMNVD
CNA3.7
EPSS
0.1%
top 70.94%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 11

Description

On Unix, SAP BusinessObjects Business Intelligence Platform (Scheduling) allows an authenticated attacker with administrator access on the local server to access the password of a local account. As a result, an attacker can obtain non-administrative user credentials, which will allow them to read or modify the remote server files.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:NExploitability: 0.8 | Impact: 5.2

Affected Packages2 packages

Patches

🔴Vulnerability Details

2
CVEList
Information Disclosure vulnerability in SAP BusinessObjects Business Intelligence Platform (Scheduling)2024-06-11
GHSA
GHSA-prf2-4xjw-553w: On Unix, SAP BusinessObjects Business Intelligence Platform (Scheduling) allows an authenticated attacker with administrator access on the local serve2024-06-11
CVE-2024-34684 — Sensitive Information Exposure | cvebase