First published: Tue Dec 13 2022(Updated: )
SAP Business Objects Platform - versions 420, and 430, allows an attacker with normal BI user privileges to upload/replace any file on Business Objects server at the operating system level, enabling the attacker to take full control of the system causing a high impact on confidentiality, integrity, and availability of the application.
Credit: cna@sap.com
Affected Software | Affected Version | How to fix |
---|---|---|
SAP Business Objects Business Intelligence Platform | =420 | |
SAP Business Objects Business Intelligence Platform | =430 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2022-41267.
The severity of CVE-2022-41267 is critical with a CVSS score of 8.8.
SAP Business Objects Platform versions 420 and 430 are affected by CVE-2022-41267.
CVE-2022-41267 can cause a high impact on confidentiality, integrity, and availability of the system.
An attacker with normal BI user privileges can upload/replace any file on the Business Objects server at the operating system level, enabling them to take full control of the system.