Vulnerability Description
In SAP BusinessObjects Business Intelligence Platform, if Single Signed On is enabled on Enterprise authentication, an unauthorized user can get a logon token using a REST endpoint. The attacker can fully compromise the system resulting in High impact on confidentiality, integrity and availability.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Sap | Business Objects Business Intelligence Platform | enterprise_430 |
Related Weaknesses (CWE)
References
- https://me.sap.com/notes/3479478Permissions Required
- https://url.sap/sapsecuritypatchdayVendor Advisory
FAQ
What is CVE-2024-41730?
CVE-2024-41730 is a vulnerability with a CVSS score of 9.8 (CRITICAL). In SAP BusinessObjects Business Intelligence Platform, if Single Signed On is enabled on Enterprise authentication, an unauthorized user can get a logon token using a REST endpoint. The attacker can f...
How severe is CVE-2024-41730?
CVE-2024-41730 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2024-41730?
Check the references section above for vendor advisories and patch information. Affected products include: Sap Business Objects Business Intelligence Platform.