Lucene search

K
nvd[email protected]NVD:CVE-2023-30740
HistoryMay 09, 2023 - 2:15 a.m.

CVE-2023-30740

2023-05-0902:15:12
CWE-200
web.nvd.nist.gov
2
cve-2023-30740
sap businessobjects
authenticated attacker
sensitive information
confidentiality
integrity
application

CVSS3

7.6

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

LOW

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L

AI Score

6.3

Confidence

High

EPSS

0.001

Percentile

35.2%

SAP BusinessObjects Business Intelligence Platform - versions 420, 430, allows an authenticated attacker to access sensitive information which is otherwise restricted. On successful exploitation, there could be a high impact on confidentiality, limited impact on integrity and availability of the application.

Affected configurations

Nvd
Node
sapbusinessobjects_business_intelligenceMatch420
OR
sapbusinessobjects_business_intelligenceMatch430
VendorProductVersionCPE
sapbusinessobjects_business_intelligence420cpe:2.3:a:sap:businessobjects_business_intelligence:420:*:*:*:*:*:*:*
sapbusinessobjects_business_intelligence430cpe:2.3:a:sap:businessobjects_business_intelligence:430:*:*:*:*:*:*:*

CVSS3

7.6

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

LOW

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L

AI Score

6.3

Confidence

High

EPSS

0.001

Percentile

35.2%

Related for NVD:CVE-2023-30740