CVE-2022-31598

MEDIUM

SAP Business Objects <420 - Info Disclosure

Title source: llm
STIX 2.1

Description

Due to insufficient input validation, SAP Business Objects - version 420, allows an authenticated attacker to submit a malicious request through an allowed operation. On successful exploitation, an attacker can view or modify information causing a limited impact on confidentiality and integrity of the application.

References (2)

Core 2
Core References
Permissions Required, Vendor Advisory x_refsource_misc
https://launchpad.support.sap.com/#/notes/3213279

Scores

CVSS v3 5.4
EPSS 0.0011
EPSS Percentile 28.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

Details

CWE
CWE-345
Status published
Products (1)
sap/business_objects_business_intelligence_platform 420
Published Jul 12, 2022
Tracked Since Feb 18, 2026