PT-2023-21946 · Sap · Sap Businessobjects Bi Platform

Published

2023-05-09

·

Updated

2023-05-12

·

CVE-2023-28764

CVSS v3.1

5.9

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions SAP BusinessObjects Platform versions 420, 430
Description The Information design tool in SAP BusinessObjects Platform transmits sensitive information as cleartext in the binaries over the network. This could allow an unauthenticated attacker with deep knowledge to gain sensitive information such as user credentials and domain names, which may have a low impact on confidentiality and no impact on the integrity and availability of the system.
Recommendations For versions 420 and 430, consider restricting access to the Information design tool to minimize the risk of exploitation until a patch is available. As a temporary workaround, avoid using the Information design tool for sensitive operations until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Insufficiently Protected Credentials

Weakness Enumeration

Related Identifiers

CVE-2023-28764

Affected Products

Sap Businessobjects Bi Platform