CVE-2023-40622: Information Disclosure vulnerability in SAP BusinessObjects Business Intelligence Platform (Promotion Management)
SAP BusinessObjects Business Intelligence Platform (Promotion Management) - versions 420, 430, under certain condition allows an authenticated attacker to view sensitive information which is otherwise restricted. On successful exploitation, the attacker can completely compromise the application causing high impact on confidentiality, integrity, and availability.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this SAP BusinessObjects Business Intelligence Platform vulnerability?
The vulnerability ID is CVE-2023-40622.
What is the severity of CVE-2023-40622?
The severity of CVE-2023-40622 is critical with a severity value of 9.9.
Which versions of SAP BusinessObjects Business Intelligence Platform are affected by CVE-2023-40622?
Versions 420 and 430 of SAP BusinessObjects Business Intelligence Platform are affected by CVE-2023-40622.
How can an authenticated attacker exploit CVE-2023-40622?
An authenticated attacker can exploit CVE-2023-40622 to view sensitive information which is otherwise restricted.
Are there any references available for CVE-2023-40622?
Yes, you can find references for CVE-2023-40622 at the following links: [Reference 1](https://me.sap.com/notes/3320355) and [Reference 2](https://www.sap.com/documents/2022/02/fa865ea4-167e-0010-bca6-c68f7e60039b.html).