CVE-2023-40622 is a critical vulnerability affecting SAP BusinessObjects Business Intelligence Platform versions 420 and 430, specifically within the Promotion Management component. An authenticated attacker can exploit this flaw to view restricted sensitive information, leading to a complete compromise of the application with high impact on confidentiality, integrity, and availability. With a CVSS score of 9.9 (Critical), this vulnerability is easily exploitable over the network with low privileges and no user interaction. While no public exploit code or active exploitation has been confirmed, the vulnerability has garnered some community discussion and media coverage, indicating awareness within the security landscape.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
420CPE matchmatch criteria | cpe:2.3:a:sap:businessobjects_business_intelligence:420:*:*:*:*:*:*:* | ||
430CPE matchmatch criteria | cpe:2.3:a:sap:businessobjects_business_intelligence:430:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 1.0 Bluesky, 0.5 Mastodon, and 1.6 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.