CVE-2018-2446

HIGH

SAP BusinessObjects Business Intelligence 4.1 4.2 - Unauthenticated Information Disclosure

Title source: llm
STIX 2.1

Description

Admin tools in SAP BusinessObjects Business Intelligence, versions 4.1, 4.2, allow an unauthenticated user to read sensitive information (server name), hence leading to an information disclosure.

References (3)

Core 3
Core References
Permissions Required, Vendor Advisory x_refsource_misc
https://launchpad.support.sap.com/#/notes/2633846
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/105089

Scores

CVSS v3 7.5
EPSS 0.0067
EPSS Percentile 71.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Details

Status published
Products (2)
sap/businessobjects_business_intelligence 4.1
sap/businessobjects_business_intelligence 4.2
Published Aug 14, 2018
Tracked Since Feb 18, 2026