CVE-2022-32246: SQL Injection
SAP Busines Objects Business Intelligence Platform (Visual Difference Application) - versions 420, 430, allows an authenticated attacker who has access to BI admin console to send crafted queries and extract data from the SQL backend. On successful exploitation, the attacker can cause limited impact on confidentiality and integrity of the application
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this SAP Business Objects Business Intelligence Platform vulnerability?
The vulnerability ID is CVE-2022-32246.
What is the severity of CVE-2022-32246?
The severity of CVE-2022-32246 is medium with a CVSS score of 4.6.
Which versions of SAP Business Objects Business Intelligence Platform are affected by CVE-2022-32246?
Versions 420 and 430 of SAP Business Objects Business Intelligence Platform are affected by CVE-2022-32246.
What is the impact of exploiting CVE-2022-32246?
Successful exploitation of CVE-2022-32246 allows an authenticated attacker to send crafted queries and extract data from the SQL backend, causing limited impact.
How can I fix CVE-2022-32246?
Apply the necessary patches and updates provided by SAP to fix CVE-2022-32246.