First published: Tue Jun 11 2024(Updated: )
On Unix, SAP BusinessObjects Business Intelligence Platform (Scheduling) allows an authenticated attacker with administrator access on the local server to access the password of a local account. As a result, an attacker can obtain non-administrative user credentials, which will allow them to read or modify the remote server files.
Credit: cna@sap.com
Affected Software | Affected Version | How to fix |
---|---|---|
SAP BusinessObjects Business Intelligence Platform | =420 | |
SAP BusinessObjects Business Intelligence Platform | =430 | |
SAP BusinessObjects Business Intelligence Platform | =440 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-34684 has been classified as a high severity vulnerability due to its potential for critical information exposure.
To fix CVE-2024-34684, apply the latest security patches provided by SAP for the affected BusinessObjects Business Intelligence Platform versions.
CVE-2024-34684 affects users with administrator access on local servers running SAP BusinessObjects Business Intelligence Platform versions 420, 430, and 440.
CVE-2024-34684 is a local privilege escalation vulnerability that allows access to sensitive information.
Exploitation of CVE-2024-34684 can lead to unauthorized access to non-administrative user credentials, potentially compromising user accounts.