2024-10-08 06:03:17 +00:00
{
"id" : "CVE-2024-37179" ,
"sourceIdentifier" : "cna@sap.com" ,
"published" : "2024-10-08T04:15:06.600" ,
2024-11-14 19:03:30 +00:00
"lastModified" : "2024-11-14T17:35:54.067" ,
"vulnStatus" : "Analyzed" ,
2024-10-08 06:03:17 +00:00
"cveTags" : [ ] ,
"descriptions" : [
{
"lang" : "en" ,
"value" : "SAP BusinessObjects Business Intelligence Platform allows an authenticated user to send a specially crafted request to the Web Intelligence Reporting Server to download any file from the machine hosting the service, causing high impact on confidentiality of the application."
2024-10-10 14:03:23 +00:00
} ,
{
"lang" : "es" ,
"value" : "SAP BusinessObjects Business Intelligence Platform permite que un usuario autenticado env\u00ede una solicitud especialmente manipulada al servidor de informes Web Intelligence para descargar cualquier archivo de la m\u00e1quina que aloja el servicio, lo que provoca un alto impacto en la confidencialidad de la aplicaci\u00f3n."
2024-10-08 06:03:17 +00:00
}
] ,
"metrics" : {
"cvssMetricV31" : [
2024-11-14 19:03:30 +00:00
{
2024-12-08 03:06:42 +00:00
"source" : "cna@sap.com" ,
"type" : "Secondary" ,
2024-11-14 19:03:30 +00:00
"cvssData" : {
"version" : "3.1" ,
2024-12-08 03:06:42 +00:00
"vectorString" : "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N" ,
"baseScore" : 7.7 ,
"baseSeverity" : "HIGH" ,
2024-11-14 19:03:30 +00:00
"attackVector" : "NETWORK" ,
"attackComplexity" : "LOW" ,
"privilegesRequired" : "LOW" ,
"userInteraction" : "NONE" ,
2024-12-08 03:06:42 +00:00
"scope" : "CHANGED" ,
2024-11-14 19:03:30 +00:00
"confidentialityImpact" : "HIGH" ,
"integrityImpact" : "NONE" ,
2024-12-08 03:06:42 +00:00
"availabilityImpact" : "NONE"
2024-11-14 19:03:30 +00:00
} ,
2024-12-08 03:06:42 +00:00
"exploitabilityScore" : 3.1 ,
"impactScore" : 4.0
2024-11-14 19:03:30 +00:00
} ,
2024-10-08 06:03:17 +00:00
{
2024-12-08 03:06:42 +00:00
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
2024-10-08 06:03:17 +00:00
"cvssData" : {
"version" : "3.1" ,
2024-12-08 03:06:42 +00:00
"vectorString" : "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" ,
"baseScore" : 6.5 ,
"baseSeverity" : "MEDIUM" ,
2024-10-08 06:03:17 +00:00
"attackVector" : "NETWORK" ,
"attackComplexity" : "LOW" ,
"privilegesRequired" : "LOW" ,
"userInteraction" : "NONE" ,
2024-12-08 03:06:42 +00:00
"scope" : "UNCHANGED" ,
2024-10-08 06:03:17 +00:00
"confidentialityImpact" : "HIGH" ,
"integrityImpact" : "NONE" ,
2024-12-08 03:06:42 +00:00
"availabilityImpact" : "NONE"
2024-10-08 06:03:17 +00:00
} ,
2024-12-08 03:06:42 +00:00
"exploitabilityScore" : 2.8 ,
"impactScore" : 3.6
2024-10-08 06:03:17 +00:00
}
]
} ,
"weaknesses" : [
{
"source" : "cna@sap.com" ,
"type" : "Primary" ,
"description" : [
{
"lang" : "en" ,
"value" : "CWE-434"
}
]
}
] ,
2024-11-14 19:03:30 +00:00
"configurations" : [
{
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:sap:businessobjects_business_intelligence:420:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "38BA0DF9-D893-4AF9-923E-E47EA5C02C52"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:sap:businessobjects_business_intelligence:430:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "85CBCF48-5478-4EE5-8F69-6E59EFDB707D"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:sap:businessobjects_business_intelligence:2025:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "DB02105F-097A-43AD-B9CC-8D45CEDD1732"
}
]
}
]
}
] ,
2024-10-08 06:03:17 +00:00
"references" : [
{
"url" : "https://me.sap.com/notes/3478615" ,
2024-11-14 19:03:30 +00:00
"source" : "cna@sap.com" ,
"tags" : [
"Permissions Required"
]
2024-10-08 06:03:17 +00:00
} ,
{
"url" : "https://url.sap/sapsecuritypatchday" ,
2024-11-14 19:03:30 +00:00
"source" : "cna@sap.com" ,
"tags" : [
"Vendor Advisory"
]
2024-10-08 06:03:17 +00:00
}
]
}