CVE-2022-35169

MEDIUM

SAP BusinessObjects BI Platform 420, 430 - Sensitive Info Exposure via LCMBIAR Password Decryption

Title source: llm
STIX 2.1

Description

SAP BusinessObjects Business Intelligence Platform (LCM) - versions 420, 430, allows an attacker with an admin privilege to read and decrypt LCMBIAR file's password under certain conditions, enabling the attacker to modify the password or import the file into another system causing high impact on confidentiality but a limited impact on the availability and integrity of the application.

References (2)

Core 2
Core References
Permissions Required, Vendor Advisory x_refsource_misc
https://launchpad.support.sap.com/#/notes/3194361

Scores

CVSS v3 6.0
EPSS 0.0043
EPSS Percentile 62.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:L

Details

CWE
CWE-200
Status published
Products (2)
sap/businessobjects_business_intelligence_platform 420
sap/businessobjects_business_intelligence_platform 430
Published Jul 12, 2022
Tracked Since Feb 18, 2026