Under specific conditions, the Central Management Console of the SAP BusinessObjects Business Intelligence platform allows an attacker with admin rights to generate or retrieve a secret passphrase, enabling them to impersonate any user in the system. This results in a high impact on confidentiality and integrity, with no impact on availability.
History

Tue, 11 Feb 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 11 Feb 2025 01:00:00 +0000

Type Values Removed Values Added
Description Under specific conditions, the Central Management Console of the SAP BusinessObjects Business Intelligence platform allows an attacker with admin rights to generate or retrieve a secret passphrase, enabling them to impersonate any user in the system. This results in a high impact on confidentiality and integrity, with no impact on availability.
Title Improper Authorization in SAP BusinessObjects Business Intelligence platform (Central Management Console)
Weaknesses CWE-732
References
Metrics cvssV3_1

{'score': 8.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: sap

Published: 2025-02-11T00:33:03.769Z

Updated: 2025-02-18T18:07:53.865Z

Reserved: 2024-12-05T21:53:07.644Z

Link: CVE-2025-0064

cve-icon Vulnrichment

Updated: 2025-02-11T14:48:06.249Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-02-11T01:15:09.803

Modified: 2025-02-18T18:15:28.470

Link: CVE-2025-0064

cve-icon Redhat

No data.