CVE-2024-41730: Missing Authentication check in SAP BusinessObjects Business Intelligence Platform
In SAP BusinessObjects Business Intelligence Platform, if Single Signed On is enabled on Enterprise authentication, an unauthorized user can get a logon token using a REST endpoint. The attacker can fully compromise the system resulting in High impact on confidentiality, integrity and availability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-41730?
CVE-2024-41730 has a high severity due to the potential for unauthorized users to gain a logon token and compromise the system.
How do I fix CVE-2024-41730?
To fix CVE-2024-41730, it is recommended to apply the latest security patches provided by SAP for versions 430 and 440.
What impact does CVE-2024-41730 have on my system?
CVE-2024-41730 can lead to significant impacts on confidentiality, integrity, and availability due to unauthorized access.
Who is affected by CVE-2024-41730?
CVE-2024-41730 affects users of SAP BusinessObjects Business Intelligence Platform versions enterprise_430 and enterprise_440.
What kind of attack can exploit CVE-2024-41730?
CVE-2024-41730 can be exploited by an attacker using a REST endpoint to bypass Enterprise authentication.