First published: Tue Oct 11 2022(Updated: )
SAP BusinessObjects Business Intelligence platform (Analysis for OLAP) - versions 420, 430, allows an authenticated attacker to send user-controlled inputs when OLAP connections are created and edited in the Central Management Console. On successful exploitation, there could be a limited impact on confidentiality and integrity of the application.
Credit: cna@sap.com
Affected Software | Affected Version | How to fix |
---|---|---|
SAP BusinessObjects Business Intelligence | =420 | |
SAP BusinessObjects Business Intelligence | =430 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this SAP BusinessObjects Business Intelligence platform vulnerability is CVE-2022-41206.
The severity of CVE-2022-41206 is medium with a CVSS score of 5.4.
The affected software for CVE-2022-41206 is SAP BusinessObjects Business Intelligence platform versions 420 and 430.
An authenticated attacker can exploit CVE-2022-41206 by sending user-controlled inputs when creating or editing OLAP connections in the Central Management Console.
The impact of successfully exploiting CVE-2022-41206 is limited.