SAP BusinessObjects Business Intelligence Platform - versions 420, 430, allows an authenticated attacker with administrator privileges to get the login token of any logged-in BI user over the network without any user interaction. The attacker can impersonate any user on the platform resulting into accessing and modifying data. The attacker can also make the system partially or entirely unavailable.
History

Tue, 28 Jan 2025 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: sap

Published: 2023-05-09T00:53:27.588Z

Updated: 2025-01-28T16:26:20.913Z

Reserved: 2023-03-23T04:20:27.699Z

Link: CVE-2023-28762

cve-icon Vulnrichment

Updated: 2024-08-02T13:51:37.301Z

cve-icon NVD

Status : Modified

Published: 2023-05-09T01:15:08.777

Modified: 2024-11-21T07:55:57.293

Link: CVE-2023-28762

cve-icon Redhat

No data.