CVE-2024-41730Missing Authorization in SE SAP Businessobjects Business Intelligence Platform

Severity
9.8CRITICALNVD
EPSS
14.3%
top 5.59%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 13
Latest updateNov 22

Description

In SAP BusinessObjects Business Intelligence Platform, if Single Signed On is enabled on Enterprise authentication, an unauthorized user can get a logon token using a REST endpoint. The attacker can fully compromise the system resulting in High impact on confidentiality, integrity and availability.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages2 packages

🔴Vulnerability Details

2
CVEList
Missing Authentication check in SAP BusinessObjects Business Intelligence Platform2024-08-13
GHSA
GHSA-fg4w-vj95-g2c7: In SAP BusinessObjects Business Intelligence Platform, if Single Signed On is enabled on Enterprise authentication, an unauthorized user can get a log2024-08-13

🔍Detection Rules

1
Suricata
ET WEB_SPECIFIC_APPS SAP BusinessObjects Business Intelligence Platform Authentication Bypass Attempt (CVE-2024-41730)2024-11-22

🕵️Threat Intelligence

1
Bleepingcomputer
Critical SAP flaw allows remote attackers to bypass authentication2024-08-13
CVE-2024-41730 — Missing Authorization | cvebase