CVE-2022-41267: Malicious File Upload
SAP Business Objects Platform - versions 420, and 430, allows an attacker with normal BI user privileges to upload/replace any file on Business Objects server at the operating system level, enabling the attacker to take full control of the system causing a high impact on confidentiality, integrity, and availability of the application.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of this SAP Business Objects Platform vulnerability?
The vulnerability ID is CVE-2022-41267.
What is the severity of CVE-2022-41267?
The severity of CVE-2022-41267 is critical with a CVSS score of 8.8.
Which versions of SAP Business Objects Platform are affected by CVE-2022-41267?
SAP Business Objects Platform versions 420 and 430 are affected by CVE-2022-41267.
What is the impact of CVE-2022-41267?
CVE-2022-41267 can cause a high impact on confidentiality, integrity, and availability of the system.
How can an attacker exploit CVE-2022-41267?
An attacker with normal BI user privileges can upload/replace any file on the Business Objects server at the operating system level, enabling them to take full control of the system.