← Vulnerability feed

Vulnerability record · CVE-2023-28764 · published 9 May 2023

CVE-2023-28764: Sap businessobjects insufficiently protected credentials vulnerability

Sap · Businessobjects

SAP BusinessObjects Platform - versions 420, 430, Information design tool transmits sensitive information as cleartext in the binaries over the network. This could allow an unauthenticated attacker with deep knowledge to gain sensitive information such as user credentials and domain names, which may have a low impact on confidentiality and no impact on the integrity and availability of the system.

5.9 CVSS 3.1 Medium EPSS 0.51% · top 58.7% CWE-522 · Insufficiently protected credentials
5.9CVSS 3.1 base score
0.51%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

SAP BusinessObjects Platform - versions 420, 430, Information design tool transmits sensitive information as cleartext in the binaries over the network. This could allow an unauthenticated attacker with deep knowledge to gain sensitive information such as user credentials and domain names, which may have a low impact on confidentiality and no impact on the integrity and availability of the system.

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-28764 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2015-7730Sap businessobjects memory buffer overflow vulnerabilitySAP BusinessObjects BI Platform 4.1, BusinessObjects Edge 4.0, and BusinessObjects XI (BOXI) 3.1 R3 allow remote attackers to cause a denial of servi…EPSS 3.6%10.0CVE-2014-9387Sap businessobjects permissions and access controls vulnerabilitySAP BusinessObjects Edge 4.1 allows remote attackers to obtain the SI_PLATFORM_SEARCH_SERVER_LOGON_TOKEN token and gain privileges via a crafted CORB…EPSS 4.6%10.0CVE-2010-0219Apache Axis2 default admin password enables remote code executionApache Axis2, as bundled in products such as SAP BusinessObjects Enterprise XI 3.2 and CA ARCserve D2D r15, ships with a default password of 'axis2' …EPSS 91%analysed9.8CVE-2019-0259Sap businessobjects unrestricted file upload vulnerabilitySAP BusinessObjects, versions 4.2 and 4.3, (Visual Difference) allows an attacker to upload any file (including script files) without proper file for…EPSS 2.0%9.0CVE-2010-3983Sap businessobjects permissions and access controls vulnerabilityCmcApp in SAP BusinessObjects Enterprise XI 3.2 allows remote authenticated users to gain privileges via vectors involving the Program Job Server and…EPSS 1.7%7.8CVE-2022-28214Sap businessobjects cleartext storage of sensitive data vulnerabilityDuring an update of SAP BusinessObjects Enterprise, Central Management Server (CMS) - versions 420, 430, authentication credentials are being exposed…EPSS 0.17%7.6CVE-2019-0287Sap businessobjects vulnerabilityUnder certain conditions SAP BusinessObjects Business Intelligence platform (Central Management Server), versions 4.2 and 4.3, allows an attacker to …EPSS 1.7%7.3CVE-2018-2408Sap businessobjects vulnerabilityImproper Session Management in SAP Business Objects, 4.0, from 4.10, from 4.20, 4.30, CMC/BI Launchpad/Fiorified BI Launchpad. In case of password ch…EPSS 1.5%

Source: NIST National Vulnerability Database (record CVE-2023-28764), CISA KEV, FIRST EPSS (scores of 2026-09-30). This page is refreshed as NVD updates the record.