During an update of SAP BusinessObjects Enterprise, Central Management Server (CMS) - versions 420, 430, authentication credentials are being exposed in Sysmon event logs. This Information Disclosure could cause a high impact on systems’ Confidentiality, Integrity, and Availability.
2022-05-11T15:15:09.730
2024-11-21T06:56:57.753
Modified
CVSSv3.1: 7.8 (HIGH)
AV:L/AC:L/Au:N/C:P/I:P/A:P
3.9
6.4
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | sap | businessobjects | 420 | Yes |
Application | sap | businessobjects | 430 | Yes |
Application | sap | businessobjects_business_intelligence | 420 | Yes |
Application | sap | businessobjects_business_intelligence | 430 | Yes |