First published: Tue May 09 2023(Updated: )
SAP BusinessObjects Business Intelligence Platform - versions 420, 430, allows an authenticated attacker with administrator privileges to get the login token of any logged-in BI user over the network without any user interaction. The attacker can impersonate any user on the platform resulting into accessing and modifying data. The attacker can also make the system partially or entirely unavailable.
Credit: cna@sap.com
Affected Software | Affected Version | How to fix |
---|---|---|
SAP BusinessObjects Business Intelligence | =420 | |
SAP BusinessObjects Business Intelligence | =430 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2023-28762.
The severity level of CVE-2023-28762 is critical with a score of 7.2.
Versions 420 and 430 of SAP BusinessObjects Business Intelligence Platform are affected by this vulnerability.
An authenticated attacker with administrator privileges can obtain the login token of any logged-in BI user and impersonate them on the platform.
Apply the necessary security patches provided by SAP to mitigate this vulnerability.