CVE-2024-41730

CRITICAL

SAP BusinessObjects Business Intelligence Platform - Unauthenticated Missing Authorization via REST Endpoint

Title source: llm
STIX 2.1

Description

In SAP BusinessObjects Business Intelligence Platform, if Single Signed On is enabled on Enterprise authentication, an unauthorized user can get a logon token using a REST endpoint. The attacker can fully compromise the system resulting in High impact on confidentiality, integrity and availability.

References (2)

Core 2
Core References
Permissions Required
https://me.sap.com/notes/3479478

Scores

CVSS v3 9.8
EPSS 0.1426
EPSS Percentile 94.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-862
Status published
Products (2)
sap/business_objects_business_intelligence_platform enterprise_430
sap/business_objects_business_intelligence_platform enterprise_440
Published Aug 13, 2024
Tracked Since Feb 18, 2026