Medium severity6.5NVD Advisory· Published Mar 14, 2023· Updated Jun 17, 2026
CVE-2023-27896
CVE-2023-27896
Description
In SAP BusinessObjects Business Intelligence Platform - version 420, 430, an attacker can control a malicious BOE server, forcing the application server to connect to its own CMS, leading to a high impact on availability.
Affected products
4cpe:2.3:a:sap:businessobjects_business_intelligence:420:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:sap:businessobjects_business_intelligence:420:*:*:*:*:*:*:*
- cpe:2.3:a:sap:businessobjects_business_intelligence:430:*:*:*:*:*:*:*
420, 430+ 1 more
- (no CPE)range: 420, 430
- (no CPE)range: 420
Patches
Vulnerability mechanics
References
2- www.sap.com/documents/2022/02/fa865ea4-167e-0010-bca6-c68f7e60039b.htmlnvdVendor Advisory
- launchpad.support.sap.comnvdPermissions Required
News mentions
0No linked articles in our index yet.