CVE-2022-35228: CSRF
SAP BusinessObjects CMC allows an unauthenticated attacker to retrieve token information over the network which would otherwise be restricted. This can be achieved only when a legitimate user accesses the application and a local compromise occurs, like sniffing or social engineering. On successful exploitation, the attacker can completely compromise the application.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this SAP BusinessObjects CMC vulnerability?
The vulnerability ID for this SAP BusinessObjects CMC vulnerability is CVE-2022-35228.
What is the severity level of CVE-2022-35228?
The severity level of CVE-2022-35228 is high.
What software is affected by CVE-2022-35228?
The SAP BusinessObjects Business Intelligence Platform versions 4.2 and 4.3 are affected by CVE-2022-35228.
How can an attacker exploit CVE-2022-35228?
An unauthenticated attacker can exploit CVE-2022-35228 by retrieving token information over the network, which would otherwise be restricted.
Are there any references or sources for more information about CVE-2022-35228?
Yes, you can find more information about CVE-2022-35228 in the SAP Support Launchpad and on the SAP website.