CVE-2023-28762
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
09/05/2023
Last modified:
12/05/2023
Description
SAP BusinessObjects Business Intelligence Platform - versions 420, 430, allows an authenticated attacker with administrator privileges to get the login token of any logged-in BI user over the network without any user interaction. The attacker can impersonate any user on the platform resulting into accessing and modifying data. The attacker can also make the system partially or entirely unavailable.<br />
<br />
Impact
Base Score 3.x
7.20
Severity 3.x
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:sap:businessobjects_business_intelligence:420:*:*:*:*:*:*:* | ||
| cpe:2.3:a:sap:businessobjects_business_intelligence:430:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



