Due to the lack of validation, SAP BusinessObjects Business Intelligence Platform (Version Management System) - version 403, permits an unauthenticated user to read the code snippet through the UI, which leads to low impact on confidentiality and no impact on the application's availability or integrity.
References
Link | Resource |
---|---|
https://me.sap.com/notes/3352453 | Permissions Required |
https://www.sap.com/documents/2022/02/fa865ea4-167e-0010-bca6-c68f7e60039b.html | Vendor Advisory |
Configurations
History
No history.
Information
Published : 2023-09-12 02:15
Updated : 2023-09-14 02:07
NVD link : CVE-2023-37489
Mitre link : CVE-2023-37489
CVE.ORG link : CVE-2023-37489
JSON object : View
Products Affected
sap
- businessobjects_business_intelligence
CWE
CWE-209
Generation of Error Message Containing Sensitive Information