6
CVE-2024-34684
- EPSS 0.11%
- Veröffentlicht 11.06.2024 03:15:10
- Zuletzt bearbeitet 21.11.2024 09:19:11
- Quelle cna@sap.com
- CVE-Watchlists
- Unerledigt
Information Disclosure vulnerability in SAP BusinessObjects Business Intelligence Platform (Scheduling)
On Unix, SAP BusinessObjects Business Intelligence Platform (Scheduling) allows an authenticated attacker with administrator access on the local server to access the password of a local account. As a result, an attacker can obtain non-administrative user credentials, which will allow them to read or modify the remote server files.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
SAP ≫ Businessobjects Business Intelligence Platform Version420 SwEditionenterprise
SAP ≫ Businessobjects Business Intelligence Platform Version430
SAP ≫ Businessobjects Business Intelligence Platform Version440
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.11% | 0.292 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 6 | 0.8 | 5.2 |
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N
|
| cna@sap.com | 3.7 | 0.6 | 2.7 |
CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:C/C:L/I:L/A:N
|
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.