Cleartext storage of sensitive information in SAP BusinessObjects Business Intelligence suite - CVE-2023-39440
Published: August 9, 2023
SAP BusinessObjects Business Intelligence suite
SAP
Description
The vulnerability allows a local user to gain access to sensitive information.
The vulnerability exists due to application stores user's credentials in plain text in memory. If a victim logs into a particular program, under certain specific conditions memory might not be cleared up properly. A local user can read memory contents, extract credentials of another user and login to the application.