Source Code Exposure in SAP Business Objects Web Intelligence by SAP
CVE-2021-33667
4.3MEDIUM
Key Information:
- Vendor
- SAP
- Vendor
- CVE Published:
- 14 July 2021
Summary
Certain versions of SAP Business Objects Web Intelligence, specifically version 420 and 430, are susceptible to a vulnerability that enables attackers to gain unauthorized access to JSP source code through SDK calls within the Analytical Reporting bundle. This breach can lead to further exploitation, as sensitive information and application logic may be exposed, thereby compromising the integrity and confidentiality of the application.
Affected Version(s)
SAP Business Objects Web Intelligence (BI Launchpad) < 420 < 420
SAP Business Objects Web Intelligence (BI Launchpad) < 430 < 430
References
CVSS V3.1
Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved