First published: Tue Jul 12 2022(Updated: )
SAP Busines Objects Business Intelligence Platform (Visual Difference Application) - versions 420, 430, allows an authenticated attacker who has access to BI admin console to send crafted queries and extract data from the SQL backend. On successful exploitation, the attacker can cause limited impact on confidentiality and integrity of the application
Credit: cna@sap.com
Affected Software | Affected Version | How to fix |
---|---|---|
SAP Business Objects Business Intelligence Platform | =420 | |
SAP Business Objects Business Intelligence Platform | =430 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2022-32246.
The severity of CVE-2022-32246 is medium with a CVSS score of 4.6.
Versions 420 and 430 of SAP Business Objects Business Intelligence Platform are affected by CVE-2022-32246.
Successful exploitation of CVE-2022-32246 allows an authenticated attacker to send crafted queries and extract data from the SQL backend, causing limited impact.
Apply the necessary patches and updates provided by SAP to fix CVE-2022-32246.