First published: Tue Aug 09 2022(Updated: )
SAP BusinessObjects Business Intelligence Platform (Open Document) - versions 420, 430, allows an unauthenticated attacker to retrieve sensitive information plain text over the network. On successful exploitation, the attacker can view any data available for a business user and put load on the application by an automated attack. Thus, completely compromising confidentiality but causing a limited impact on the availability of the application.
Credit: cna@sap.com
Affected Software | Affected Version | How to fix |
---|---|---|
SAP BusinessObjects Business Intelligence | =420 | |
SAP BusinessObjects Business Intelligence | =430 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-32245 is a vulnerability in SAP BusinessObjects Business Intelligence Platform (Open Document) versions 420 and 430 that allows an unauthenticated attacker to retrieve sensitive information in plain text over the network.
CVE-2022-32245 has a severity rating of 8.2, which is considered high.
An attacker can exploit CVE-2022-32245 by retrieving sensitive information in plain text over the network.
CVE-2022-32245 affects versions 420 and 430 of SAP BusinessObjects Business Intelligence Platform.
Yes, SAP has released patches and security notes to address CVE-2022-32245. It is recommended to apply the latest updates and follow the security guidelines provided by SAP.