CVE-2014-9320: Critical severity sap businessobjects vulnerability
Published Aug 9, 2021
·Updated
SAP BusinessObjects Edge 4.1 allows remote attackers to obtain the SIPLATFORMSEARCHSERVERLOGONTOKEN token and consequently gain SYSTEM privileges via vectors involving CORBA calls, aka SAP Note 2039905.
Affected Software
1 affected component
SAP BusinessObjects Edge=4.1
Remediation
Patch Available
Event History
Aug 9, 2021
CVE Published
via MITRE·06:03 PM
Data Sourced
via MITRE·06:03 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-9320?
CVE-2014-9320 has been classified with a high severity level due to the potential for remote privilege escalation.
2
How do I fix CVE-2014-9320?
To fix CVE-2014-9320, it is recommended to upgrade to a patched version of SAP BusinessObjects Edge that addresses this vulnerability.
3
What is the impact of CVE-2014-9320?
The impact of CVE-2014-9320 allows attackers to obtain system-level privileges by exploiting CORBA calls.
4
Which versions of SAP are affected by CVE-2014-9320?
CVE-2014-9320 specifically affects SAP BusinessObjects Edge version 4.1.
5
Can CVE-2014-9320 be exploited remotely?
Yes, CVE-2014-9320 can be exploited remotely by attackers to gain unauthorized access.