CVE-2023-28762
CRITICALSAP BusinessObjects Business Intelligence Platform - versions 420, ...
Title source: llmDescription
SAP BusinessObjects Business Intelligence Platform - versions 420, 430, allows an authenticated attacker with administrator privileges to get the login token of any logged-in BI user over the network without any user interaction. The attacker can impersonate any user on the platform resulting into accessing and modifying data. The attacker can also make the system partially or entirely unavailable.
References (2)
Core 2
Core References
Permissions Required
https://launchpad.support.sap.com/#/notes/3307833
Scores
CVSS v3
9.1
EPSS
0.0045
EPSS Percentile
64.0%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
CWE
CWE-200
Status
published
Products (2)
sap/businessobjects_business_intelligence
420
sap/businessobjects_business_intelligence
430
Published
May 09, 2023
Tracked Since
Feb 18, 2026