← Back to browse · API

CVE-2024-41730

Severity
CRITICAL
CVSS
9.8
EPSS
0.75866
Risk score
65.75
CISA KEV
No
PoC
No
Published
2024-08-13
Modified
2024-08-16
First seen
2026-08-07
Aliases
EUVD-2024-39173, GHSA-FG4W-VJ95-G2C7
Products
SAP_SE:SAP BusinessObjects Business Intelligence Platform 440, SAP_SE:SAP BusinessObjects Business Intelligence Platform ENTERPRISE 430
Sources
euvd EUVD-2024-39173

Description

In SAP BusinessObjects Business Intelligence Platform, if Single Signed On is enabled on Enterprise authentication, an unauthorized user can get a logon token using a REST endpoint. The attacker can fully compromise the system resulting in High impact on confidentiality, integrity and availability.

References