CVE-2024-28166: Multiple Unrestricted File Upload vulnerabilities in SAP BusinessObjects Business Intelligence Platform
SAP BusinessObjects Business Intelligence Platform allows an authenticated attacker to upload malicious code over the network, that could be executed by the application. On successful exploitation, the attacker can cause a low impact on the Integrity of the application.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-28166?
The severity of CVE-2024-28166 is assessed as low impact on the Integrity of the application.
How do I fix CVE-2024-28166?
To fix CVE-2024-28166, ensure you apply the latest security patches provided by SAP for the affected versions.
Which versions of SAP BusinessObjects Business Intelligence Platform are affected by CVE-2024-28166?
CVE-2024-28166 affects SAP Business Objects Business Intelligence Platform versions 430, 440, and enterprise 420.
What type of vulnerability is CVE-2024-28166?
CVE-2024-28166 is a code injection vulnerability that allows an authenticated attacker to upload and execute malicious code.
What are the potential impacts of exploiting CVE-2024-28166?
Exploitation of CVE-2024-28166 can lead to a low impact on the integrity of the application, potentially compromising its functionality.