First published: Tue Apr 09 2024(Updated: )
Due to improper validation, SAP BusinessObject Business Intelligence Launch Pad allows an authenticated attacker to access operating system information using crafted document. On successful exploitation there could be a considerable impact on confidentiality of the application.
Credit: cna@sap.com
Affected Software | Affected Version | How to fix |
---|---|---|
SAP BusinessObjects Business Intelligence | ||
SAP BusinessObjects Business Intelligence |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-25646 has been classified with a high severity due to its potential for significant confidentiality breaches.
To address CVE-2024-25646, apply the latest security update provided by SAP for the affected products.
CVE-2024-25646 affects SAP BusinessObjects Business Intelligence Launch Pad and SAP BusinessObjects Web Intelligence.
The exploitation of CVE-2024-25646 could lead to unauthorized access to sensitive operating system information.
CVE-2024-25646 can be exploited by authenticated attackers who can craft specific documents to launch their attacks.