SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2023-28762

SAP BusinessObjects Business Intelligence Platform - versions 420, 430, allows an authenticated attacker with administrator privileges to get the login token of any logged-in BI user over the network without any user interaction.

HIGH 7.2EPSS 0.71%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (0.71%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

SAP BusinessObjects Business Intelligence Platform - versions 420, 430, allows an authenticated attacker with administrator privileges to get the login token of any logged-in BI user over the network without any user interaction. The attacker can impersonate any user on the platform resulting into accessing and modifying data. The attacker can also make the system partially or entirely unavailable.

CVSS 3.1
7.2 HIGHCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
EPSS
0.71% probability · 52th percentile
CISA KEV
Not listed
Weakness
CWE-200
Affected
sap/businessobjects business intelligence
Source
cna@sap.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.