Insufficient Input Validation in SAP Business Objects API
CVE-2022-31598
5.4MEDIUM
Summary
An insufficient input validation vulnerability in SAP Business Objects version 420 enables authenticated attackers to execute malicious requests via authorized operations. Upon successful exploitation, attackers may gain unauthorized access to sensitive information or alter existing data, thereby posing a risk to the confidentiality and integrity of the application's data.
Affected Version(s)
SAP Business Objects 420
References
CVSS V3.1
Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved