CVE-2022-22541

MEDIUM

SAP BusinessObjects Business Intelligence Platform <430 - Info Disc...

Title source: llm
STIX 2.1

Description

SAP BusinessObjects Business Intelligence Platform - versions 420, 430, may allow legitimate users to access information they shouldn't see through relational or OLAP connections. The main impact is the disclosure of company data to people that shouldn't or don't need to have access.

References (2)

Core 2
Core References
Permissions Required, Vendor Advisory x_refsource_misc
https://launchpad.support.sap.com/#/notes/3137191

Scores

CVSS v3 6.5
EPSS 0.0029
EPSS Percentile 51.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-213
Status published
Products (2)
sap/businessobjects_business_intelligence_platform 420
sap/businessobjects_business_intelligence_platform 430
Published Apr 12, 2022
Tracked Since Feb 18, 2026