PT-2024-25050 · Sap · Sap Businessobjects Business Intelligence Platform

Published

2024-05-14

·

Updated

2024-09-28

·

CVE-2024-33004

CVSS v3.1

4.3

Medium

VectorAV:P/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions SAP Business Objects Business Intelligence Platform (affected versions not specified)
Description The issue concerns insecure storage where dynamic web pages are cached even after a user logs out. This allows an attacker to potentially view sensitive information through the cache and access pages, resulting in limited impact on the confidentiality, integrity, and availability of the application.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Insecure Storage of Sensitive Information

Weakness Enumeration

Related Identifiers

CVE-2024-33004

Affected Products

Sap Businessobjects Business Intelligence Platform