CVE-2023-28765
CVSS V2 None
CVSS V3 None
Description
An attacker with basic privileges in SAP BusinessObjects Business Intelligence Platform (Promotion Management) - versions 420, 430, can get access to lcmbiar file and further decrypt the file. After this attacker can gain access to BI user’s passwords and depending on the privileges of the BI user, the attacker can perform operations that can completely compromise the application.
Overview
- CVE ID
- CVE-2023-28765
- Assigner
- cna@sap.com
- Vulnerability Status
- Analyzed
- Published Version
- 2023-04-11T03:15:07
- Last Modified Date
- 2023-04-14T19:49:59
Weakness Enumerations
CPE Configuration (Product)
CPE | Vulnerable | Operator | Version Start | Version End |
---|---|---|---|---|
cpe:2.3:a:sap:businessobjects_business_intelligence:420:*:*:*:*:*:*:* | 1 | OR | ||
cpe:2.3:a:sap:businessobjects_business_intelligence:430:*:*:*:*:*:*:* | 1 | OR |
References
Reference URL | Reference Tags |
---|---|
https://launchpad.support.sap.com/#/notes/3298961 | Permissions Required |
https://www.sap.com/documents/2022/02/fa865ea4-167e-0010-bca6-c68f7e60039b.html | Vendor Advisory |
Sources
Source Name | Source URL |
---|---|
NIST | https://nvd.nist.gov/vuln/detail/CVE-2023-28765 |
MITRE | https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-28765 |
History
Created | Old Value | New Value | Data Type | Notes |
---|---|---|---|---|
2023-04-17 04:28:28 | Added to TrackCVE | |||
2023-04-17 04:28:30 | Weakness Enumeration | new |