Rewterz
Rewterz Threat Advisory – CVE-2022-35293 – SAP Enable Now Manager Vulnerability
August 11, 2022
Rewterz
Rewterz Threat Alert – Agent Tesla Malware – Active IOCs
August 11, 2022

Rewterz Threat Advisory – Multiple SAP BusinessObjects Business Intelligence Platform Vulnerabilities

Severity

Medium

Analysis Summary

CVE-2022-31596 CVSS:5.2
SAP BusinessObjects Business Intelligence Platform could allow a remote authenticated attacker to obtain sensitive information, caused by an unspecified flaw. By sending a specially-crafted request, an attacker could exploit this vulnerability to obtain sensitive information, and use this information to launch further attacks against the affected system.

CVE-2022-32244 CVSS:5.2
SAP BusinessObjects Business Intelligence Platform could allow a remote authenticated attacker to obtain sensitive information, caused by an unspecified flaw. By sending a specially-crafted request, an attacker could exploit this vulnerability to obtain sensitive information, and use this information to launch further attacks against the affected system.

CVE-2022-32245 CVSS:8.2
SAP BusinessObjects Business Intelligence Platform could allow a remote attacker to obtain sensitive information, caused by the transmission of sensitive information in plain text. By sniffing the network traffic, an attacker could exploit this vulnerability to obtain sensitive information for a business user, and put load on the application to cause a denial of service condition.

Impact

  • Information Disclosure

Indicators Of Compromise

CVE

  • CVE-2022-31596
  • CVE-2022-32244
  • CVE-2022-32245

Affected Vendors

SAP

Affected Products

  • SAP BusinessObjects Business Intelligence Platform 430
  • SAP BusinessObjects Business Intelligence Platform 420

Remediation

Current SAP customers should refer to SAP for patch information, available from the SAP Web site (login required).

SAP Website