First published: Tue Apr 12 2022(Updated: )
A CSRF token visible in the URL may possibly lead to information disclosure vulnerability.
Credit: cna@sap.com
Affected Software | Affected Version | How to fix |
---|---|---|
Sap Businessobjects Business Intelligence Platform | =420 | |
Sap Businessobjects Business Intelligence Platform | =430 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this CSRF token information disclosure vulnerability is CVE-2022-27671.
The severity of CVE-2022-27671 is medium with a CVSS score of 6.5.
SAP BusinessObjects Business Intelligence Platform versions 4.20 and 4.30 are affected by CVE-2022-27671.
The vulnerability in SAP BusinessObjects Business Intelligence Platform allows an attacker to potentially disclose sensitive information by exploiting a CSRF token that is visible in the URL.
You can find more information about CVE-2022-27671 in the SAP Security Note 3130497 and the SAP advisory document.