Vulnerabilities > CVE-2022-32244 - Unspecified vulnerability in SAP Businessobjects Business Intelligence 420/430
Attack vector
ADJACENT_NETWORK Attack complexity
LOW Privileges required
HIGH Confidentiality impact
LOW Integrity impact
HIGH Availability impact
NONE low complexity
sap
Summary
Under certain conditions an attacker authenticated as a CMS administrator access the BOE Commentary database and retrieve (non-personal) system data, modify system data but can't make the system unavailable. This needs the attacker to have high privilege access to the same physical/logical network to access information which would otherwise be restricted, leading to low impact on confidentiality and high impact on integrity of the application.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 2 |