Server Side Request Forgery (SSRF) in the SAP BusinessObjects Business Intelligence platform
CVE-2023-27271
6.5MEDIUM
Key Information:
- Vendor
SAP
- Vendor
- CVE Published:
- 14 March 2023
What is CVE-2023-27271?
A vulnerability exists in the SAP BusinessObjects Business Intelligence Platform that allows an attacker to take control of a malicious BOE server. This manipulation forces the application server to establish connections to its own administrative tools, leading to significant disruptions in system availability. The affected versions, 420 and 430, are particularly susceptible, making it crucial for users to address this issue promptly.
Affected Version(s)
BusinessObjects Business Intelligence Platform (Web Services) 420
BusinessObjects Business Intelligence Platform (Web Services) 430