Vulnerabilities > CVE-2024-41730 - Missing Authorization vulnerability in SAP Business Objects Business Intelligence Platform Enterprise430/Enterprise440
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
HIGH Integrity impact
HIGH Availability impact
HIGH Summary
In SAP BusinessObjects Business Intelligence Platform, if Single Signed On is enabled on Enterprise authentication, an unauthorized user can get a logon token using a REST endpoint. The attacker can fully compromise the system resulting in High impact on confidentiality, integrity and availability.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 2 |