CVE-2023-27271: Server Side Request Forgery (SSRF) in the SAP BusinessObjects Business Intelligence platform
In SAP BusinessObjects Business Intelligence Platform (Web Services) - versions 420, 430, an attacker can control a malicious BOE server, forcing the application server to connect to its own admintools, leading to a high impact on availability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-27271?
The severity of CVE-2023-27271 is high.
What software versions are affected by CVE-2023-27271?
CVE-2023-27271 affects SAP BusinessObjects Business Intelligence Platform versions 420 and 430.
How can an attacker exploit CVE-2023-27271?
An attacker can control a malicious BOE server, forcing the application server to connect to its own admintools, leading to a high impact on availability.
Is there a fix available for CVE-2023-27271?
Yes, SAP has provided patches and fixes for CVE-2023-27271. Please refer to the official SAP notes for more information.
Are there any additional resources for CVE-2023-27271?
Yes, you can find more information about CVE-2023-27271 in the SAP support notes and the official SAP documentation.