CVE-2024-37179
CVSS 3.1 Score 6.5 of 10 (medium)
Details
Summary
CVE-2024-37179 is a vulnerability affecting the SAP BusinessObjects Business Intelligence Platform. This issue enables authenticated users to download any file from the hosting machine by sending a crafted request to the Web Intelligence Reporting Server, leading to a significant confidentiality risk. Unauthorized access to sensitive files can result in serious consequences, making this a high-severity vulnerability that should be addressed promptly. SAP has released patches to mitigate the issue; it is strongly recommended that users apply these updates to protect their systems.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- SAP Business Objects Business Intelligence
Affected Vendors
- SAP SE