First published: Tue Jul 12 2022(Updated: )
SAP BusinessObjects CMC allows an unauthenticated attacker to retrieve token information over the network which would otherwise be restricted. This can be achieved only when a legitimate user accesses the application and a local compromise occurs, like sniffing or social engineering. On successful exploitation, the attacker can completely compromise the application.
Credit: cna@sap.com
Affected Software | Affected Version | How to fix |
---|---|---|
Sap Businessobjects Business Intelligence Platform | =420 | |
Sap Businessobjects Business Intelligence Platform | =430 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this SAP BusinessObjects CMC vulnerability is CVE-2022-35228.
The severity level of CVE-2022-35228 is high.
The SAP BusinessObjects Business Intelligence Platform versions 4.2 and 4.3 are affected by CVE-2022-35228.
An unauthenticated attacker can exploit CVE-2022-35228 by retrieving token information over the network, which would otherwise be restricted.
Yes, you can find more information about CVE-2022-35228 in the SAP Support Launchpad and on the SAP website.