漏洞标题
SAP Business Objects Business Intelligence Platform信息泄露漏洞
漏洞描述信息
由于SAP Business Objects Business Intelligence Platform在错误处理中存在不当操作,导致应用程序的技术细节在异常和堆栈跟踪中被透露给用户。仅有具备管理员级别权限的攻击者能够访问这些被披露的信息,并利用这些信息来进一步策划攻击。该漏洞不会影响应用程序的完整性和可用性。
CVSS信息
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:L
漏洞类别
通过错误消息导致的信息暴露
漏洞标题
Information Disclosure in SAP Business Objects Business Intelligence Platform
漏洞描述信息
Due to improper error handling in SAP Business Objects Business Intelligence Platform, technical details of the application are revealed in exceptions thrown to the user and in stack traces. Only an attacker with administrator level privileges has access to this disclosed information, and they could use it to craft further exploits. There is no impact on the integrity and availability of the application.
CVSS信息
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:N/A:N
漏洞类别
通过错误消息导致的信息暴露