Due to improper validation, SAP BusinessObject Business Intelligence Launch Pad allows an authenticated attacker to access operating system information using crafted document. On successful exploitation there could be a considerable impact on confidentiality of the application.
Metrics
Affected Vendors & Products
References
History
Sat, 28 Sep 2024 23:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-200 |
Sat, 28 Sep 2024 23:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Sat, 28 Sep 2024 22:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Due to improper validation, SAP BusinessObject Business Intelligence Launch Pad allows an authenticated attacker to access operating system information using crafted document. On successful exploitation there could be a considerable impact on confidentiality of the application. | Due to improper validation, SAP BusinessObject Business Intelligence Launch Pad allows an authenticated attacker to access operating system information using crafted document. On successful exploitation there could be a considerable impact on confidentiality of the application. |
Weaknesses | CWE-732 |
MITRE
Status: PUBLISHED
Assigner: sap
Published: 2024-04-09T00:47:43.364Z
Updated: 2024-09-28T22:25:36.576Z
Reserved: 2024-02-09T04:10:20.037Z
Link: CVE-2024-25646
Vulnrichment
Updated: 2024-08-01T23:44:09.878Z
NVD
Status : Awaiting Analysis
Published: 2024-04-09T01:15:48.343
Modified: 2024-11-21T09:01:08.960
Link: CVE-2024-25646
Redhat
No data.