CVE-2022-39013
HIGHSAP Business Objects Business Intelligence Platform - Authenticated Exposure of OS Credentials
Title source: llmDescription
Under certain conditions an authenticated attacker can get access to OS credentials. Getting access to OS credentials enables the attacker to modify system data and make the system unavailable leading to high impact on confidentiality and low impact on integrity and availability of the application.
References (2)
Core 2
Core References
Permissions Required, Vendor Advisory
https://launchpad.support.sap.com/#/notes/3229132
Scores
CVSS v3
7.6
EPSS
0.0049
EPSS Percentile
65.9%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L
Details
CWE
CWE-200
Status
published
Products (2)
sap/business_objects_business_intelligence_platform
420
sap/business_objects_business_intelligence_platform
430
Published
Oct 11, 2022
Tracked Since
Feb 18, 2026