CVE-2022-35228
Published: Jul 12, 2022
Modified: Aug 3, 2024
Description
SAP BusinessObjects CMC allows an unauthenticated attacker to retrieve token information over the network which would otherwise be restricted. This can be achieved only when a legitimate user accesses the application and a local compromise occurs, like sniffing or social engineering. On successful exploitation, the attacker can completely compromise the application.
| Vendor | Product | Versions |
|---|---|---|
SAP SE | SAP BusinessObjects Business Intelligence Platform (Central management Console) | affected 420affected 430 |
Weaknesses (CWE)
References
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now