CVE-2024-45281

Published Sep 10, 2024

Last updated 2 months ago

Overview

Description
SAP BusinessObjects Business Intelligence Platform allows a high privilege user to run client desktop applications even if some of the DLLs are not digitally signed or if the signature is broken. The attacker needs to have local access to the vulnerable system to perform DLL related tasks. This could result in a high impact on confidentiality and integrity of the application.
Source
cna@sap.com
NVD status
Awaiting Analysis

Risk scores

CVSS 3.1

Type
Secondary
Base score
5.8
Impact score
5.2
Exploitability score
0.6
Vector string
CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:N
Severity
MEDIUM

Weaknesses

cna@sap.com
CWE-426

Social media

Hype score
Not currently trending