Medium severity4.6NVD Advisory· Published Jul 12, 2022· Updated Jun 17, 2026
CVE-2022-32246
CVE-2022-32246
Description
SAP Busines Objects Business Intelligence Platform (Visual Difference Application) - versions 420, 430, allows an authenticated attacker who has access to BI admin console to send crafted queries and extract data from the SQL backend. On successful exploitation, the attacker can cause limited impact on confidentiality and integrity of the application
Affected products
4cpe:2.3:a:sap:business_objects_business_intelligence_platform:420:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:sap:business_objects_business_intelligence_platform:420:*:*:*:*:*:*:*
- cpe:2.3:a:sap:business_objects_business_intelligence_platform:430:*:*:*:*:*:*:*
- SAP SE/SAP BusinessObjects Business Intelligence Platform (Visual Difference Application)v5Range: 420
- Range: 420, 430
Patches
Vulnerability mechanics
References
2- launchpad.support.sap.comnvdPermissions RequiredVendor Advisory
- www.sap.com/documents/2022/02/fa865ea4-167e-0010-bca6-c68f7e60039b.htmlnvdVendor Advisory
News mentions
0No linked articles in our index yet.