CVE-2024-32732

MEDIUM

SAP BusinessObjects - Info Disclosure

Title source: llm
STIX 2.1

Description

Under certain conditions SAP BusinessObjects Business Intelligence platform allows an attacker to access information which would otherwise be restricted.This has low impact on Confidentiality with no impact on Integrity and Availability of the application.

References (2)

Core 2
Core References
Permissions Required
https://me.sap.com/notes/3524933

Scores

CVSS v3 5.3
EPSS 0.0030
EPSS Percentile 21.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-497
Status published
Products (2)
sap/businessobjects_business_intelligence_platform 430
sap/businessobjects_business_intelligence_platform 2025
Published Dec 10, 2024
Tracked Since Feb 18, 2026