CVE-2024-37179

Severity
6.5MEDIUM
EPSS
0.5%
top 32.68%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 8

Description

SAP BusinessObjects Business Intelligence Platform allows an authenticated user to send a specially crafted request to the Web Intelligence Reporting Server to download any file from the machine hosting the service, causing high impact on confidentiality of the application.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:NExploitability: 3.1 | Impact: 4.0

🔴Vulnerability Details

2
GHSA
GHSA-gc4w-ffjr-829q: SAP BusinessObjects Business Intelligence Platform allows an authenticated user to send a specially crafted request to the Web Intelligence Reporting2024-10-08
CVEList
Insecure File Operations vulnerability in SAP BusinessObjects Business Intelligence Platform (Web Intelligence)2024-10-08
CVE-2024-37179 (MEDIUM CVSS 6.5) | SAP BusinessObjects Business Intell | cvebase.io