CVE-2023-31404: Information Disclosure in SAP BusinessObjects Business Intelligence Platform (Central Management Service)
Under certain conditions, SAP BusinessObjects Business Intelligence Platform (Central Management Service) - versions 420, 430, allows an attacker to access information which would otherwise be restricted. Some users with specific privileges could have access to credentials of other users. It could let them access data sources which would otherwise be restricted.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2023-31404.
What is the severity of CVE-2023-31404?
CVE-2023-31404 has a medium severity.
Which software versions are affected by CVE-2023-31404?
Versions 420 and 430 of SAP BusinessObjects Business Intelligence Platform (Central Management Service) are affected by CVE-2023-31404.
What is the impact of CVE-2023-31404?
CVE-2023-31404 allows an attacker to access restricted information and obtain credentials of other users.
Are there any references for CVE-2023-31404?
Yes, you can find references for CVE-2023-31404 at the following links: [Reference 1](https://launchpad.support.sap.com/#/notes/3038911), [Reference 2](https://www.sap.com/documents/2022/02/fa865ea4-167e-0010-bca6-c68f7e60039b.html).