CVE-2022-27671: CSRF
Published Apr 12, 2022
·Updated
A CSRF token visible in the URL may possibly lead to information disclosure vulnerability.
Affected Software
2 affected components
SAP BusinessObjects Business Intelligence platform=420
SAP BusinessObjects Business Intelligence platform=430
Event History
Apr 12, 2022
CVE Published
via MITRE·04:11 PM
Data Sourced
via MITRE·04:11 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this CSRF token information disclosure vulnerability?
The vulnerability ID for this CSRF token information disclosure vulnerability is CVE-2022-27671.
2
What is the severity of CVE-2022-27671?
The severity of CVE-2022-27671 is medium with a CVSS score of 6.5.
3
What software is affected by CVE-2022-27671?
SAP BusinessObjects Business Intelligence Platform versions 4.20 and 4.30 are affected by CVE-2022-27671.
4
How does the vulnerability in SAP BusinessObjects Business Intelligence Platform lead to information disclosure?
The vulnerability in SAP BusinessObjects Business Intelligence Platform allows an attacker to potentially disclose sensitive information by exploiting a CSRF token that is visible in the URL.
5
Where can I find more information about CVE-2022-27671?
You can find more information about CVE-2022-27671 in the SAP Security Note 3130497 and the SAP advisory document.