SAP BusinessObjects Business Intelligence Platform allows an authenticated user to send a specially crafted request to the Web Intelligence Reporting Server to download any file from the machine hosting the service, causing high impact on confidentiality of the application.
oryginał ENCVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:NSap Businessobjects Business Intelligence
APPSap2025420430
🟢
PATCH DOSTĘPNY
Aktualizacja od producenta gotowa. Wdrożenie w ramach standardowego cyklu.
CWE
Powiązane podatności
CVE-2023-40622CRITICAL9.9PL ✓ten sam produkt
SAP BusinessObjects BI Platform – nieautoryzowany dostęp do wrażliwych danych
CVE-2023-28762CRITICAL9.1PL ✓ten sam produkt
SAP BusinessObjects BI Platform — kradzież tokenu logowania przez admina
CVE-2023-28765CRITICAL9.8PL ✓ten sam produkt
SAP BusinessObjects BI Platform — ujawnienie i odszyfrowanie haseł użytkowników
CVE-2018-2445CRITICAL9.6PL ✓ten sam produkt
SSRF w SAP BusinessObjects BI — AdminTools (CVE-2018-2445)
CVE-2025-23192HIGH8.2ten sam produkt
SAP BusinessObjects Business Intelligence (BI Workspace) allows an unauthenticated attacker to craft and store...