CVE-2022-41203

HIGH

SAP BusinessObjects BI Platform - Deserialization

Title source: llm

Description

In some workflow of SAP BusinessObjects BI Platform (Central Management Console and BI LaunchPad), an authenticated attacker with low privileges can intercept a serialized object in the parameters and substitute with another malicious serialized object, which leads to deserialization of untrusted data vulnerability. This could highly compromise the Confidentiality, Integrity, and Availability of the system.

Scores

CVSS v3 8.8
EPSS 0.0097
EPSS Percentile 76.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Classification

CWE
CWE-502
Status published

Affected Products (2)

sap/businessobjects_business_intelligence
sap/businessobjects_business_intelligence

Timeline

Published Nov 08, 2022
Tracked Since Feb 18, 2026