Lucene search

K
cveSapCVE-2024-28166
HistoryAug 13, 2024 - 4:15 a.m.

CVE-2024-28166

2024-08-1304:15:06
CWE-434
sap
web.nvd.nist.gov
23
sap businessobjects
bi platform
authenticated
code execution
network
low impact
integrity

CVSS3

4.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

AI Score

4.4

Confidence

High

EPSS

0

Percentile

14.7%

SAP BusinessObjects Business Intelligence
Platform allows an authenticated attacker to upload malicious code over the
network, that could be executed by the application. On successful
exploitation, the attacker can cause a low impact on the Integrity of the
application.

Affected configurations

Nvd
Node
sapbusiness_objects_business_intelligence_platformMatch430
OR
sapbusiness_objects_business_intelligence_platformMatch440
OR
sapbusiness_objects_business_intelligence_platformMatchenterprise_420
VendorProductVersionCPE
sapbusiness_objects_business_intelligence_platform430cpe:2.3:a:sap:business_objects_business_intelligence_platform:430:*:*:*:*:*:*:*
sapbusiness_objects_business_intelligence_platform440cpe:2.3:a:sap:business_objects_business_intelligence_platform:440:*:*:*:*:*:*:*
sapbusiness_objects_business_intelligence_platformenterprise_420cpe:2.3:a:sap:business_objects_business_intelligence_platform:enterprise_420:*:*:*:*:*:*:*

CNA Affected

[
  {
    "defaultStatus": "unaffected",
    "product": "SAP BusinessObjects Business Intelligence Platform",
    "vendor": "SAP_SE",
    "versions": [
      {
        "status": "affected",
        "version": "ENTERPRISE 420"
      },
      {
        "status": "affected",
        "version": "430"
      },
      {
        "status": "affected",
        "version": "440"
      }
    ]
  }
]

CVSS3

4.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

AI Score

4.4

Confidence

High

EPSS

0

Percentile

14.7%

Related for CVE-2024-28166