← Volver a CVEs
CVE-2024-33004
MEDIUM4.3
Descripcion
SAP Business Objects Business Intelligence Platform is vulnerable to Insecure Storage as dynamic web pages are getting cached even after logging out. On successful exploitation, the attacker can see the sensitive information through cache and can open the pages causing limited impact on Confidentiality, Integrity and Availability of the application.
Detalles CVE
Puntuacion CVSS v3.14.3
SeveridadMEDIUM
Vector CVSSCVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Vector de ataquePHYSICAL
ComplejidadLOW
Privilegios requeridosNONE
Interaccion usuarioNONE
Publicado5/14/2024
Ultima modificacion10/23/2025
Fuentenvd
Avistamientos honeypot0
Productos afectados
sap:businessobjects_business_intelligence_platform
Debilidades (CWE)
CWE-524CWE-922
Referencias
https://me.sap.com/notes/3449093(cna@sap.com)
https://me.sap.com/notes/3449093(af854a3a-2127-422b-91ae-364da2661108)
https://support.sap.com/en/my-support/knowledge-base/security-notes-news.html(af854a3a-2127-422b-91ae-364da2661108)
Correlaciones IOC
Sin correlaciones registradas
This product uses data from the NVD API but is not endorsed or certified by the NVD.