PT-2022-3938 · Sap · Sap Businessobjects Business Intelligence Platform

Published

2022-04-25

·

Updated

2023-07-21

·

CVE-2022-29619

CVSS v2.0

8.5

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:N
Name of the Vulnerable Software and Affected Versions SAP BusinessObjects Business Intelligence Platform version 4.x - versions 4.20, 4.30
Description The issue is related to incorrect authorization in the SAP BusinessObjects Business Intelligence Platform. Under certain conditions, it allows an Administrator user to view, edit, or modify rights of objects that it does not own and that would otherwise be restricted. This could potentially enable a remote attacker to gain access to modify, add, or delete data.
Recommendations For SAP BusinessObjects Business Intelligence Platform version 4.x - versions 4.20, 4.30, consider restricting access to sensitive objects until a proper authorization mechanism is implemented to prevent unauthorized modifications. As a temporary workaround, review and limit the privileges of the Administrator user to minimize the risk of exploitation.

Fix

Incorrect Authorization

Weakness Enumeration

Related Identifiers

BDU:2022-04767
CVE-2022-29619

Affected Products

Sap Businessobjects Business Intelligence Platform