CVE-2019-0287

HIGH

SAP BusinessObjects <4.3 - Info Disclosure

Title source: llm
STIX 2.1

Description

Under certain conditions SAP BusinessObjects Business Intelligence platform (Central Management Server), versions 4.2 and 4.3, allows an attacker to access information which would otherwise be restricted.

References (3)

Core 3
Core References
Permissions Required x_refsource_misc
https://launchpad.support.sap.com/#/notes/2737278
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/108316

Scores

CVSS v3 7.6
EPSS 0.0047
EPSS Percentile 64.7%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:L

Details

Status published
Products (2)
sap/businessobjects 4.2
sap/businessobjects 4.3
Published May 14, 2019
Tracked Since Feb 18, 2026