CVE-2025-23185
CVE-2025-23185
Título es
CVE-2025-23185
Mar, 11/03/2025 – 01:15
Tipo
CWE-209
Gravedad 2.0 Txt
Pendiente de análisis
Título en
CVE-2025-23185
Descripción en
Due to improper error handling in SAP Business Objects Business Intelligence Platform, technical details of the application are revealed in exceptions thrown to the user and in stack traces. Only an attacker with administrator level privileges has access to this disclosed information, and they could use it to craft further exploits. There is no impact on the integrity and availability of the application.
11/03/2025
11/03/2025
Vector CVSS:3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:N/A:N
Gravedad 3.1 (CVSS 3.1 Base Score)
4.10
Gravedad 3.1 Txt Gravedad 3.1 (CVSS 3.1 Base Score)
MEDIUM
Referencias
https://me.sap.com/notes/3549494
https://url.sap/sapsecuritypatchday
Enviar en el boletín
Off
