PT-2024-6827 · Sap · Sap Businessobjects Business Intelligence Platform

Published

2024-08-12

·

Updated

2024-12-10

·

CVE-2024-28166

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions SAP BusinessObjects Business Intelligence Platform (affected versions not specified)
Description The issue is related to the unrestricted upload of dangerous file types, which can be exploited by a remote attacker to impact the integrity of protected information. An authenticated attacker can upload malicious code over the network, which could be executed by the application, causing a low impact on the application's integrity.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

BDU:2024-08047
CVE-2024-28166

Affected Products

Sap Businessobjects Business Intelligence Platform