PT-2022-25775 · Sap · Sap Businessobjects Business Intelligence Platform

Published

2022-12-12

·

Updated

2023-07-11

·

CVE-2022-41263

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions SAP Business Objects Business Intelligence Platform (Web Intelligence) versions 420, 430
Description The issue is caused by a missing authentication check, allowing an authenticated non-administrator attacker to modify the data source information for a document that is otherwise restricted. On successful exploitation, the attacker can modify information, causing a limited impact on the integrity of the application.
Recommendations For versions 420 and 430, consider restricting access to the document data source information to prevent unauthorized modifications until a patch is available. As a temporary workaround, limit the privileges of non-administrator users to minimize the risk of exploitation. Restrict access to sensitive documents to minimize the risk of information modification. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

CSRF

Weakness Enumeration

Related Identifiers

CVE-2022-41263

Affected Products

Sap Businessobjects Business Intelligence Platform