CRITICAL🇵🇱 Wersja polska

CVE-2023-0022

CVSS 9.9v3.1pub. 2023-01-10upd. 2024-11-21

SAP BusinessObjects Business Intelligence Analysis edition for OLAP allows an authenticated attacker to inject malicious code that can be executed by the application over the network. On successful exploitation, an attacker can perform operations that may completely compromise the application causing a high impact on the confidentiality, integrity, and availability of the application.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
  • Sap Businessobjects Business Intelligence Platform

    APP
    Sap
    420430
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2023-0018CRITICAL10.0PL ✓same product

Stored XSS w SAP BusinessObjects BI Platform CMC — CVSS 10.0

CVE-2020-26831CRITICAL9.6PL ✓same product

SAP BusinessObjects BI Platform — SSRF i ujawnienie plików przez XML Injection

CVE-2020-6294CRITICAL9.1PL ✓same product

SAP BusinessObjects BI Platform – brak uwierzytelnienia w komponencie Xvfb (Unix)

CVE-2020-6242CRITICAL9.8PL ✓same product

SAP BusinessObjects BI Platform — logowanie bez hasła do CMC (Missing Authentication)

CVE-2020-6195CRITICAL9.8PL ✓same product

SAP BusinessObjects BI Platform CMC ujawnia hasło w plaintext w odpowiedzi HTTP