cvelist/2024/32xxx/CVE-2024-32732.json

97 lines
3.2 KiB
JSON
Raw Normal View History

2024-04-17 11:00:35 +00:00
{
2024-12-10 01:00:59 +00:00
"data_version": "4.0",
2024-04-17 11:00:35 +00:00
"data_type": "CVE",
"data_format": "MITRE",
"CVE_data_meta": {
"ID": "CVE-2024-32732",
2024-12-10 01:00:59 +00:00
"ASSIGNER": "cna@sap.com",
"STATE": "PUBLIC"
2024-04-17 11:00:35 +00:00
},
"description": {
"description_data": [
{
"lang": "eng",
2024-12-10 01:00:59 +00:00
"value": "Under certain conditions SAP BusinessObjects Business Intelligence platform allows an attacker to access information which would otherwise be restricted.This has low impact on Confidentiality with no impact on Integrity and Availability of the application."
}
]
},
"problemtype": {
"problemtype_data": [
{
"description": [
{
"lang": "eng",
"value": "CWE-497: Exposure of Sensitive System Information to an Unauthorized Control Sphere",
"cweId": "CWE-497"
}
]
}
]
},
"affects": {
"vendor": {
"vendor_data": [
{
"vendor_name": "SAP_SE",
"product": {
"product_data": [
{
"product_name": "SAP BusinessObjects Business Intelligence platform",
"version": {
"version_data": [
{
"version_affected": "=",
2024-12-10 07:01:00 +00:00
"version_value": "ENTERPRISE 430"
2024-12-10 01:00:59 +00:00
},
{
"version_affected": "=",
"version_value": "2025"
}
]
}
}
]
}
}
]
}
},
"references": {
"reference_data": [
{
"url": "https://me.sap.com/notes/3524933",
"refsource": "MISC",
"name": "https://me.sap.com/notes/3524933"
},
{
"url": "https://url.sap/sapsecuritypatchday",
"refsource": "MISC",
"name": "https://url.sap/sapsecuritypatchday"
}
]
},
"generator": {
"engine": "Vulnogram 0.2.0"
},
"source": {
"discovery": "UNKNOWN"
},
"impact": {
"cvss": [
{
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 5.3,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "LOW",
"integrityImpact": "NONE",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
"version": "3.1"
2024-04-17 11:00:35 +00:00
}
]
}
}