SAP BusinessObjects Edge 4.1 allows remote attackers to obtain the SI_PLATFORM_SEARCH_SERVER_LOGON_TOKEN token and gain privileges via a crafted CORBA call, aka SAP Note 2039905.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
http://www.onapsis.com/research/security-advisories/sap-business-objects-search-token-privilege-escalation-via-corba | third party advisory |
http://seclists.org/fulldisclosure/2014/Dec/60 | mailing list vdb entry third party advisory |
http://www.securityfocus.com/archive/1/534249/100/0/threaded | mailing list |