Lucene search

K
cveSapCVE-2023-30740
HistoryMay 09, 2023 - 2:15 a.m.

CVE-2023-30740

2023-05-0902:15:12
CWE-200
sap
web.nvd.nist.gov
21
cve-2023-30740
sap businessobjects
business intelligence platform
authentication bypass
information disclosure
confidentiality impact
integrity impact
availability impact

CVSS3

7.6

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

LOW

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L

AI Score

7.1

Confidence

High

EPSS

0.001

Percentile

35.2%

SAP BusinessObjects Business Intelligence Platform - versions 420, 430, allows an authenticated attacker to access sensitive information which is otherwise restricted. On successful exploitation, there could be a high impact on confidentiality, limited impact on integrity and availability of the application.

Affected configurations

Nvd
Node
sapbusinessobjects_business_intelligenceMatch420
OR
sapbusinessobjects_business_intelligenceMatch430
VendorProductVersionCPE
sapbusinessobjects_business_intelligence420cpe:2.3:a:sap:businessobjects_business_intelligence:420:*:*:*:*:*:*:*
sapbusinessobjects_business_intelligence430cpe:2.3:a:sap:businessobjects_business_intelligence:430:*:*:*:*:*:*:*

CNA Affected

[
  {
    "defaultStatus": "unaffected",
    "product": "SAP BusinessObjects Business Intelligence Platform",
    "vendor": "SAP_SE",
    "versions": [
      {
        "status": "affected",
        "version": "420"
      },
      {
        "status": "affected",
        "version": "430"
      }
    ]
  }
]

CVSS3

7.6

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

LOW

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L

AI Score

7.1

Confidence

High

EPSS

0.001

Percentile

35.2%

Related for CVE-2023-30740