PT-2022-15511 · Sap · Sap Businessobjects Business Intelligence Platform
Published
2022-04-12
·
Updated
2022-04-20
·
CVE-2022-22541
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
SAP BusinessObjects Business Intelligence Platform versions 420, 430
Description
The issue may allow legitimate users to access information they shouldn't see through relational or OLAP connections. The main impact is the disclosure of company data to people that shouldn't or don't need to have access.
Recommendations
For versions 420 and 430, restrict access to relational and OLAP connections to minimize the risk of unauthorized data disclosure.
As a temporary workaround, consider limiting user permissions to sensitive data until a fix is available.
Avoid using relational or OLAP connections for sensitive information until the issue is resolved.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sap Businessobjects Business Intelligence Platform