CVE-2023-28765 | Information Disclosure vulnerability in SAP BusinessObjects Business Intelligence Platform (Promotion Management )
An attacker with basic privileges in SAP BusinessObjects Business Intelligence Platform (Promotion Management) - versions 420, 430, can get access to lcmbiar file and further decrypt the file. After this attacker can gain access to BI user’s passwords and depending on the privileges of the BI user, the attacker can perform operations that can completely compromise the application.
Conclusion & alert: CVE-2023-28765 is rated Moderate Risk (62.8/100): CVSS Critical severity, with medium exploitation likelihood (EPSS 0.83%).Mandatory action: Review affected assets and schedule remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
Exploit prediction scoring system (EPSS) score for CVE-2023-28765
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).