- Forget Ring - Arlo's flagship battery-powered security camera is still on sale for $120
- These might be one of my favorite exercise earbuds -- and they're still on sale
- If Musk wants AI for the world, why not open-source all the Grok models?
- xAI's Grok 3 is better than expected. How to try it for free (before you subscribe)
- Upgrade your home audio with this JBL soundbar that's still $150 off
SAP patches critical bugs allowing full system compromise
![SAP patches critical bugs allowing full system compromise SAP patches critical bugs allowing full system compromise](https://www.csoonline.com/wp-content/uploads/2024/08/3486653-0-25728000-1723634332-shutterstock_editorial_1347234716.jpg?quality=50&strip=all&w=1024)
Two critical vulnerabilities
Of the two critical vulnerabilities addressed in the patch day, the more severe is an authentication bypass flaw (CVE-2024-41730) with a CVSS score of 9.8/10 affecting SAP’s BusinessObjects business intelligence platform, while the other is a server-side request forgery (SSRF) vulnerability in applications built with SAP Build Apps.
CVE-2024-41730, as described by SAP, stems from a missing authentication check in the SAP BusinessObjects business intelligence platform. “In SAP BusinessObjects Business Intelligence Platform, if Single Signed On is enabled on Enterprise authentication, an unauthorized user can get a logon token using a REST endpoint,” the ERP vendor said in a security advisory.
The attacker can fully compromise the system resulting in a high impact on confidentiality, integrity, and availability, SAP added.