CVE-2023-27894

MEDIUM

SAP BusinessObjects BI Platform 420, 430 - Information Disclosure via CMS Injection

Title source: llm
STIX 2.1

Description

SAP BusinessObjects Business Intelligence Platform (Web Services) - versions 420, 430, allows an attacker to inject arbitrary values as CMS parameters to perform lookups on the internal network which is otherwise not accessible externally. On successful exploitation, attacker can scan internal network to determine internal infrastructure for further attacks like remote file inclusion, retrieve server files, bypass firewall and force the vulnerable server to execute malicious requests, resulting in sensitive information disclosure. This causes limited impact on confidentiality of data.

Scores

CVSS v3 5.0
EPSS 0.0038
EPSS Percentile 59.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-200
Status published
Products (2)
sap/businessobjects_business_intelligence 420
sap/businessobjects_business_intelligence 430
Published Mar 14, 2023
Tracked Since Feb 18, 2026