CVE-2023-28764

Severity CVSS v4.0:
Pending analysis
Type:
CWE-522 Insufficiently Protected Credentials
Publication date:
09/05/2023
Last modified:
12/05/2023

Description

SAP BusinessObjects Platform - versions 420, 430, Information design tool transmits sensitive information as cleartext in the binaries over the network. This could allow an unauthenticated attacker with deep knowledge to gain sensitive information such as user credentials and domain names, which may have a low impact on confidentiality and no impact on the integrity and availability of the system.<br /> <br />

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:sap:businessobjects:4.20:*:*:*:*:*:*:*
cpe:2.3:a:sap:businessobjects:4.30:*:*:*:*:*:*:*