CVE-2022-39013

HIGH

SAP Business Objects Business Intelligence Platform - Authenticated Exposure of OS Credentials

Title source: llm
STIX 2.1

Description

Under certain conditions an authenticated attacker can get access to OS credentials. Getting access to OS credentials enables the attacker to modify system data and make the system unavailable leading to high impact on confidentiality and low impact on integrity and availability of the application.

References (2)

Core 2

Scores

CVSS v3 7.6
EPSS 0.0049
EPSS Percentile 65.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L

Details

CWE
CWE-200
Status published
Products (2)
sap/business_objects_business_intelligence_platform 420
sap/business_objects_business_intelligence_platform 430
Published Oct 11, 2022
Tracked Since Feb 18, 2026