PT-2023-4259 · Sap · Sap Businessobjects Business Intelligence

Published

2023-08-08

·

Updated

2024-09-28

·

CVE-2023-39440

CVSS v3.1

4.4

Medium

VectorAV:L/AC:H/PR:L/UI:R/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions SAP BusinessObjects Business Intelligence version 420
Description The issue is related to insufficient protection of internal data in SAP BusinessObjects Business Intelligence. Under specific conditions, when a user logs in to a particular program, memory might not be properly cleared, potentially allowing an attacker to access user credentials. A successful attack requires local access to the system and does not impact availability and integrity.
Recommendations For SAP BusinessObjects Business Intelligence version 420, consider restricting local access to the system to minimize the risk of exploitation until a patch is available. As a temporary workaround, ensure that all users log out properly after using the system to reduce the risk of credential exposure.

Fix

Cleartext Storage of Sensitive Information

Information Disclosure

Weakness Enumeration

Related Identifiers

BDU:2023-04574
CVE-2023-39440

Affected Products

Sap Businessobjects Business Intelligence