CVE Vulnerabilities

CVE-2022-32244

Published: Sep 13, 2022 | Modified: Sep 20, 2022
CVSS 3.x
5.2
MEDIUM
Source:
NVD
CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:L/I:H/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

Under certain conditions an attacker authenticated as a CMS administrator access the BOE Commentary database and retrieve (non-personal) system data, modify system data but cant make the system unavailable. This needs the attacker to have high privilege access to the same physical/logical network to access information which would otherwise be restricted, leading to low impact on confidentiality and high impact on integrity of the application.

Affected Software

Name Vendor Start Version End Version
Businessobjects_business_intelligence Sap 420 (including) 420 (including)
Businessobjects_business_intelligence Sap 430 (including) 430 (including)

References