Due to improper validation, SAP BusinessObject Business Intelligence Launch Pad allows an authenticated attacker to access operating system information using crafted document. On successful exploitation there could be a considerable impact on confidentiality of the application.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-22962 | Due to improper validation, SAP BusinessObject Business Intelligence Launch Pad allows an authenticated attacker to access operating system information using crafted document. On successful exploitation there could be a considerable impact on confidentiality of the application. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 29 Oct 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Sap
Sap businessobjects Web Intelligence |
|
| CPEs | cpe:2.3:a:sap:businessobjects_web_intelligence:420:*:*:*:*:*:*:* cpe:2.3:a:sap:businessobjects_web_intelligence:430:*:*:*:*:*:*:* cpe:2.3:a:sap:businessobjects_web_intelligence:440:*:*:*:*:*:*:* |
|
| Vendors & Products |
Sap
Sap businessobjects Web Intelligence |
Sat, 28 Sep 2024 23:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-200 |
Sat, 28 Sep 2024 23:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sat, 28 Sep 2024 22:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Due to improper validation, SAP BusinessObject Business Intelligence Launch Pad allows an authenticated attacker to access operating system information using crafted document. On successful exploitation there could be a considerable impact on confidentiality of the application. | Due to improper validation, SAP BusinessObject Business Intelligence Launch Pad allows an authenticated attacker to access operating system information using crafted document. On successful exploitation there could be a considerable impact on confidentiality of the application. |
| Weaknesses | CWE-732 |
Status: PUBLISHED
Assigner: sap
Published:
Updated: 2024-09-28T22:25:36.576Z
Reserved: 2024-02-09T04:10:20.037Z
Link: CVE-2024-25646
Updated: 2024-08-01T23:44:09.878Z
Status : Analyzed
Published: 2024-04-09T01:15:48.343
Modified: 2025-10-29T14:08:12.403
Link: CVE-2024-25646
No data.
OpenCVE Enrichment
No data.
EUVD