ZeroHour

CVE-2024-25646

CVSS 3.1
6.5 medium
EPSS
<1%p35
Published
()
Modified
Description

Due to improper validation, SAP BusinessObject Business Intelligence Launch Pad allows an authenticated attacker to access operating system information using crafted document. On successful exploitation there could be a considerable impact on confidentiality of the application.

Vendors
sap
Products
businessobjects web intelligence
Weakness
CWE-732
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.