82 lines
2.7 KiB
JSON
Raw Normal View History

{
"id": "CVE-2024-33004",
"sourceIdentifier": "cna@sap.com",
"published": "2024-05-14T16:17:13.957",
"lastModified": "2024-11-21T09:16:12.917",
"vulnStatus": "Awaiting Analysis",
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "SAP Business Objects Business Intelligence Platform is vulnerable to Insecure Storage as dynamic web pages are getting cached even after logging out. On successful exploitation, the attacker can see the sensitive information through cache and can open the pages causing limited impact on Confidentiality, Integrity and Availability of the application."
},
{
"lang": "es",
"value": "SAP Business Objects Business Intelligence Platform es vulnerable al almacenamiento inseguro, ya que las p\u00e1ginas web din\u00e1micas se almacenan en cach\u00e9 incluso despu\u00e9s de cerrar la sesi\u00f3n. Si la explotaci\u00f3n tiene \u00e9xito, el atacante puede ver la informaci\u00f3n confidencial a trav\u00e9s del cach\u00e9 y abrir las p\u00e1ginas, lo que provoca un impacto limitado en la confidencialidad, la integridad y la disponibilidad de la aplicaci\u00f3n."
}
],
"metrics": {
"cvssMetricV31": [
{
"source": "cna@sap.com",
"type": "Secondary",
"cvssData": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L",
"baseScore": 4.3,
"baseSeverity": "MEDIUM",
"attackVector": "PHYSICAL",
"attackComplexity": "LOW",
"privilegesRequired": "NONE",
"userInteraction": "NONE",
"scope": "UNCHANGED",
"confidentialityImpact": "LOW",
"integrityImpact": "LOW",
"availabilityImpact": "LOW"
},
"exploitabilityScore": 0.9,
"impactScore": 3.4
}
]
},
"weaknesses": [
{
"source": "cna@sap.com",
"type": "Secondary",
"description": [
{
"lang": "en",
"value": "CWE-524"
}
]
},
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"type": "Secondary",
"description": [
{
"lang": "en",
"value": "CWE-922"
}
]
}
],
"references": [
{
"url": "https://me.sap.com/notes/3449093",
"source": "cna@sap.com"
},
{
"url": "https://support.sap.com/en/my-support/knowledge-base/security-notes-news.html",
"source": "cna@sap.com"
},
{
"url": "https://me.sap.com/notes/3449093",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://support.sap.com/en/my-support/knowledge-base/security-notes-news.html",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
]
}