CVE-2023-36917

MEDIUM

SAP BusinessObjects Business Intelligence Platform - Password Bypass

Title source: llm
STIX 2.1

Description

SAP BusinessObjects Business Intelligence Platform - version 420, 430, allows an unauthorized attacker who had hijacked a user session, to be able to bypass the victim’s old password via brute force, due to unrestricted rate limit for password change functionality. Although the attack has no impact on integrity loss or system availability, this could lead to an attacker to completely takeover a victim’s account.

References (2)

Core 2

Scores

CVSS v3 5.9
EPSS 0.0008
EPSS Percentile 23.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-307
Status published
Products (2)
sap/businessobjects_business_intelligence 420
sap/businessobjects_business_intelligence 430
Published Jul 11, 2023
Tracked Since Feb 18, 2026