First published: Tue May 09 2023(Updated: )
Due to insufficient input validation, SAP BusinessObjects Business Intelligence Platform - versions 420, 430, allows an unauthenticated attacker to redirect users to untrusted site using a malicious link. On successful exploitation, an attacker can view or modify information causing a limited impact on confidentiality and integrity of the application.
Credit: cna@sap.com
Affected Software | Affected Version | How to fix |
---|---|---|
SAP BusinessObjects Business Intelligence | =420 | |
SAP BusinessObjects Business Intelligence | =430 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2023-31406.
The title of this vulnerability is "Due to insufficient input validation SAP BusinessObjects Business Intelligence Platform - versions 420, 430."
The severity of CVE-2023-31406 is medium.
CVE-2023-31406 allows an unauthenticated attacker to redirect users to an untrusted site using a malicious link, leading to a limited impact.
To fix CVE-2023-31406, it is recommended to apply the necessary patches or updates provided by SAP.