CVE-2019-0346

MEDIUM

SAP BusinessObjects Business Intelligence Platform 4.2 - Cleartext Transmission of Sensitive Information

Title source: llm
STIX 2.1

Description

Unencrypted communication error in SAP Business Objects Business Intelligence Platform (Central Management Console), version 4.2, leads to disclosure of list of user names and roles imported from SAP NetWeaver BI systems, resulting in Information Disclosure.

References (2)

Core 2
Core References
Permissions Required, Vendor Advisory x_refsource_misc
https://launchpad.support.sap.com/#/notes/2764513

Scores

CVSS v3 6.5
EPSS 0.0017
EPSS Percentile 38.0%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-319
Status published
Products (1)
sap/businessobjects_business_intelligence 4.2
Published Aug 14, 2019
Tracked Since Feb 18, 2026