Vulnerability Details CVE-2022-41267
SAP Business Objects Platform - versions 420, and 430, allows an attacker with normal BI user privileges to upload/replace any file on Business Objects server at the operating system level, enabling the attacker to take full control of the system causing a high impact on confidentiality, integrity, and availability of the application.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 42.3%
CVSS Severity
CVSS v3 Score 9.9
Products affected by CVE-2022-41267
-
cpe:2.3:a:sap:business_objects_business_intelligence_platform:420
-
cpe:2.3:a:sap:business_objects_business_intelligence_platform:430