Lucene search

K
nvd[email protected]NVD:CVE-2022-41267
HistoryDec 13, 2022 - 3:15 a.m.

CVE-2022-41267

2022-12-1303:15:09
CWE-434
web.nvd.nist.gov
1
sap business objects
unauthorized file upload
system control
confidentiality
integrity
availability

8.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

0.001 Low

EPSS

Percentile

39.9%

SAP Business Objects Platform - versions 420, and 430, allows an attacker with normal BI user privileges to upload/replace any file on Business Objects server at the operating system level, enabling the attacker to take full control of the system causing a high impact on confidentiality, integrity, and availability of the application.

Affected configurations

NVD
Node
sapbusiness_objects_business_intelligence_platformMatch420
OR
sapbusiness_objects_business_intelligence_platformMatch430

8.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

0.001 Low

EPSS

Percentile

39.9%

Related for NVD:CVE-2022-41267