CVE-2022-41263

Due to a missing authentication check, SAP Business Objects Business Intelligence Platform (Web Intelligence) - versions 420, 430, allows an authenticated non-administrator attacker to modify the data source information for a document that is otherwise restricted. On successful exploitation, the attacker can modify information causing a limited impact on the integrity of the application.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:sap:business_objects_business_intelligence_platform:420:*:*:*:*:*:*:*
cpe:2.3:a:sap:business_objects_business_intelligence_platform:430:*:*:*:*:*:*:*

History

21 Nov 2024, 07:22

Type Values Removed Values Added
Summary
  • (es) Debido a que falta una verificación de autenticación, SAP Business Objects Business Intelligence Platform (Web Intelligence), versiones 420, 430, permite que un atacante no administrador autenticado modifique la información del origen de datos de un documento que de otro modo estaría restringido. Si la explotación tiene éxito, el atacante puede modificar la información causando un impacto limitado en la integridad de la aplicación.
References () https://launchpad.support.sap.com/#/notes/3249648 - Permissions Required, Vendor Advisory () https://launchpad.support.sap.com/#/notes/3249648 - Permissions Required, Vendor Advisory
References () https://www.sap.com/documents/2022/02/fa865ea4-167e-0010-bca6-c68f7e60039b.html - Vendor Advisory () https://www.sap.com/documents/2022/02/fa865ea4-167e-0010-bca6-c68f7e60039b.html - Vendor Advisory

Information

Published : 2022-12-12 22:15

Updated : 2024-11-21 07:22


NVD link : CVE-2022-41263

Mitre link : CVE-2022-41263

CVE.ORG link : CVE-2022-41263


JSON object : View

Products Affected

sap

  • business_objects_business_intelligence_platform
CWE
CWE-352

Cross-Site Request Forgery (CSRF)