7.7
CVE-2024-37179
- EPSS 0.21%
- Published 08.10.2024 04:15:06
- Last modified 14.11.2024 17:35:54
- Source cna@sap.com
- Teams watchlist Login
- Open Login
SAP BusinessObjects Business Intelligence Platform allows an authenticated user to send a specially crafted request to the Web Intelligence Reporting Server to download any file from the machine hosting the service, causing high impact on confidentiality of the application.
Data is provided by the National Vulnerability Database (NVD)
SAP ≫ Businessobjects Business Intelligence Version420
SAP ≫ Businessobjects Business Intelligence Version430
SAP ≫ Businessobjects Business Intelligence Version2025
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.21% | 0.431 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 6.5 | 2.8 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
|
cna@sap.com | 7.7 | 3.1 | 4 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
|
CWE-434 Unrestricted Upload of File with Dangerous Type
The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.