Vulnerabilities > CVE-2023-27896 - Server-Side Request Forgery (SSRF) vulnerability in SAP Businessobjects Business Intelligence 420/430
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
NONE Integrity impact
NONE Availability impact
HIGH Summary
In SAP BusinessObjects Business Intelligence Platform - version 420, 430, an attacker can control a malicious BOE server, forcing the application server to connect to its own CMS, leading to a high impact on availability.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 2 |