Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-36917


SAP BusinessObjects Business Intelligence Platform - version 420, 430, allows an unauthorized attacker who had hijacked a user session, to be able to bypass the victim’s old password via brute force, due to unrestricted rate limit for password change functionality. Although the attack has no impact on integrity loss or system availability, this could lead to an attacker to completely takeover a victim’s account.


Published

2023-07-11T03:15:10.117

Last Modified

2024-11-21T08:10:55.057

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 5.9 (MEDIUM)

Weaknesses
  • Type: Secondary
    CWE-307

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application sap businessobjects_business_intelligence 420 Yes
Application sap businessobjects_business_intelligence 430 Yes

References