Description
Due to improper error handling in SAP Business Objects Business Intelligence Platform, technical details of the application are revealed in exceptions thrown to the user and in stack traces. Only an attacker with administrator level privileges has access to this disclosed information, and they could use it to craft further exploits. There is no impact on the integrity and availability of the application.
CVSS breakdown
CVSS 3.1
Attack Vector
Network
Attack Complexity
Low
Privileges Required
High
User Interaction
None
Scope
Changed
Confidentiality
Low
Integrity
None
Availability
None
Affected products
- SAP_SE / SAP Business Objects Business Intelligence PlatformENTERPRISE 430 – ENTERPRISE 430
- SAP_SE / SAP Business Objects Business Intelligence Platform2025 – 2025
- SAP_SE / SAP Business Objects Business Intelligence Platform2027 – 2027