Unauthorized Access via REST Endpoint poses High Risk to Confidentiality, Integrity, and Availability
CVE-2024-41730
Key Information:
- Vendor
SAP
- Vendor
- CVE Published:
- 13 August 2024
Badges
What is CVE-2024-41730?
In SAP BusinessObjects Business Intelligence Platform, a vulnerability exists that allows an unauthorized user to obtain a logon token when Single Sign-On is enabled with Enterprise authentication. This exploit makes it possible for attackers to gain access and potentially compromise the system while impacting essential security aspects such as confidentiality, integrity, and availability. Organizations using vulnerable versions must take immediate action to mitigate risks associated with this security flaw.
Affected Version(s)
SAP BusinessObjects Business Intelligence Platform ENTERPRISE 430
SAP BusinessObjects Business Intelligence Platform 440
News Articles
References
EPSS Score
15% chance of being exploited in the next 30 days.
CVSS V3.1
Timeline
- 👾
Exploit known to exist
- 📰
First article discovered by The Cyber Express
Vulnerability published
Vulnerability Reserved