Unauthenticated Token Retrieval Vulnerability in SAP BusinessObjects CMC
CVE-2022-35228
Key Information:
- Vendor
SAP
- Vendor
- CVE Published:
- 12 July 2022
What is CVE-2022-35228?
SAP BusinessObjects CMC has a vulnerability that allows unauthenticated attackers to retrieve sensitive token information over the network. This exploitation occurs when a legitimate user is interacting with the application, creating an opportunity for local compromise through methods such as network sniffing or social engineering attacks. If successfully exploited, the attacker gains the ability to completely compromise the SAP BusinessObjects CMC application, posing a significant risk to the security of the system.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
SAP BusinessObjects Business Intelligence Platform (Central management Console) 420
SAP BusinessObjects Business Intelligence Platform (Central management Console) 430
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved