CVE-2022-41263: CSRF
Due to a missing authentication check, SAP Business Objects Business Intelligence Platform (Web Intelligence) - versions 420, 430, allows an authenticated non-administrator attacker to modify the data source information for a document that is otherwise restricted. On successful exploitation, the attacker can modify information causing a limited impact on the integrity of the application.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of this issue?
The vulnerability ID of this issue is CVE-2022-41263.
What is the severity level of CVE-2022-41263?
The severity level of CVE-2022-41263 is medium.
Which software versions are affected by CVE-2022-41263?
The SAP Business Objects Business Intelligence Platform versions 420 and 430 are affected by CVE-2022-41263.
What is the impact of CVE-2022-41263?
CVE-2022-41263 allows an authenticated non-administrator attacker to modify the data source information for a restricted document.
Are there any references for CVE-2022-41263?
Yes, you can find references for CVE-2022-41263 at the following links: [Reference 1](https://launchpad.support.sap.com/#/notes/3249648), [Reference 2](https://www.sap.com/documents/2022/02/fa865ea4-167e-0010-bca6-c68f7e60039b.html).