First published: Tue Sep 13 2022(Updated: )
Under certain conditions an attacker authenticated as a CMS administrator access the BOE Commentary database and retrieve (non-personal) system data, modify system data but can't make the system unavailable. This needs the attacker to have high privilege access to the same physical/logical network to access information which would otherwise be restricted, leading to low impact on confidentiality and high impact on integrity of the application.
Credit: cna@sap.com
Affected Software | Affected Version | How to fix |
---|---|---|
SAP BusinessObjects Business Intelligence | =420 | |
SAP BusinessObjects Business Intelligence | =430 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-32244 is a vulnerability that allows an attacker authenticated as a CMS administrator to access and modify system data in the BOE Commentary database.
To exploit CVE-2022-32244, the attacker needs to have high privilege access to the same physical/logical network as the target.
CVE-2022-32244 has a severity value of 5.2, which is considered medium.
SAP BusinessObjects Business Intelligence versions 4.2 and 4.3 are affected by CVE-2022-32244.
To fix CVE-2022-32244, apply the recommended patches and security updates provided by SAP.