CVE-2019-0331

MEDIUM

SAP BusinessObjects Business Intelligence Platform 4.1-4.3 - Information Disclosure via Directory Structure Access

Title source: llm
STIX 2.1

Description

Under certain conditions, SAP BusinessObjects Business Intelligence Platform (BI Workspace), versions 4.1, 4.2, 4.3, allows an attacker to access sensitive data such as directory structure, leading to Information Disclosure.

References (2)

Core 2
Core References
Permissions Required, Vendor Advisory x_refsource_misc
https://launchpad.support.sap.com/#/notes/2742468

Scores

CVSS v3 5.3
EPSS 0.0021
EPSS Percentile 42.7%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Details

Status published
Products (3)
sap/businessobjects_business_intelligence 4.1
sap/businessobjects_business_intelligence 4.2
sap/businessobjects_business_intelligence 4.3
Published Aug 14, 2019
Tracked Since Feb 18, 2026