CVE Published: 14/05/2024 |
CVE Updated: 28/09/2024 |
CVE Year: 2024 Source: sap |
Vendor: SAP_SE |
Product: SAP BusinessObjects Business Intelligence Platform (Webservices) Status : PUBLISHED
CVE-2024-33004 Description
SAP Business Objects Business Intelligence Platform is vulnerable to Insecure Storage as dynamic web pages are getting cached even after logging out. On successful exploitation, the attacker can see the sensitive information through cache and can open the pages causing limited impact on Confidentiality, Integrity and Availability of the application.
Metrics
CVSS Version: 3.1 |
Base Score: 4.3 MEDIUM Vector: CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L