First published: Tue Nov 08 2022(Updated: )
In some workflow of SAP BusinessObjects BI Platform (Central Management Console and BI LaunchPad), an authenticated attacker with low privileges can intercept a serialized object in the parameters and substitute with another malicious serialized object, which leads to deserialization of untrusted data vulnerability. This could highly compromise the Confidentiality, Integrity, and Availability of the system.
Credit: cna@sap.com
Affected Software | Affected Version | How to fix |
---|---|---|
SAP BusinessObjects Business Intelligence | =4.2 | |
SAP BusinessObjects Business Intelligence | =4.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2022-41203 is critical.
CVE-2022-41203 affects SAP BusinessObjects BI Platform versions 4.2 and 4.3.
An authenticated attacker with low privileges can intercept and substitute a serialized object in the parameters, leading to deserialization of untrusted data.
To fix CVE-2022-41203, apply the necessary security patches provided by SAP.
You can find more information about CVE-2022-41203 in the official SAP notes and documentation.