Skip to main content

Successful exploitation could lead to full system compromise

Summary

Successful exploitation could lead to full system compromise

Affected platforms

The following platforms are known to be affected:

Threat details

Introduction

SAP has released a security update for a missing authentication check vulnerability in BusinessObjects Business Intelligence Platform. The vulnerability, CVE-2024-41730, has a CVSSv3 score of 9.8 and could allow a remote unauthenticated attacker to obtain a logon token using a REST endpoint if Single Sign-On is enabled, potentially leading to full compromise of the system.

Threat updates

Remediation advice

Affected organisations are encouraged to review the SAP August 2024 Security NotesSAP October 2024 Security Notes, and apply any relevant updates.

Definitive source of threat updates

CVE Vulnerabilities

Last edited: 19 November 2024 4:03 pm