First published: Tue May 14 2024(Updated: )
SAP Business Objects Business Intelligence Platform is vulnerable to Insecure Storage as dynamic web pages are getting cached even after logging out. On successful exploitation, the attacker can see the sensitive information through cache and can open the pages causing limited impact on Confidentiality, Integrity and Availability of the application.
Credit: cna@sap.com
Affected Software | Affected Version | How to fix |
---|---|---|
SAP BusinessObjects Business Intelligence Platform |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-33004 is classified with a limited impact due to insecure storage issues in SAP Business Objects Business Intelligence Platform.
To fix CVE-2024-33004, implement proper cache control mechanisms to ensure that sensitive data is not cached after user logout.
CVE-2024-33004 exposes sensitive user information through cached dynamic web pages after logging out.
CVE-2024-33004 affects users of the SAP Business Objects Business Intelligence Platform.
Attackers exploiting CVE-2024-33004 can access sensitive information through cached web pages even after legitimate users have logged out.