CVE-2024-25646: Information Disclosure vulnerability in SAP BusinessObjects Web Intelligence
Due to improper validation, SAP BusinessObject Business Intelligence Launch Pad allows an authenticated attacker to access operating system information using crafted document. On successful exploitation there could be a considerable impact on confidentiality of the application.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-25646?
CVE-2024-25646 has been classified with a high severity due to its potential for significant confidentiality breaches.
How do I fix CVE-2024-25646?
To address CVE-2024-25646, apply the latest security update provided by SAP for the affected products.
What are the affected products in CVE-2024-25646?
CVE-2024-25646 affects SAP BusinessObjects Business Intelligence Launch Pad and SAP BusinessObjects Web Intelligence.
What is the impact of CVE-2024-25646 on my system?
The exploitation of CVE-2024-25646 could lead to unauthorized access to sensitive operating system information.
Who can exploit CVE-2024-25646?
CVE-2024-25646 can be exploited by authenticated attackers who can craft specific documents to launch their attacks.