CVE-2019-0348

MEDIUM

SAP BusinessObjects Business Intelligence Platform 4.1-4.2 - Cleartext Transmission of Sensitive Database Information

Title source: llm
STIX 2.1

Description

SAP BusinessObjects Business Intelligence Platform (Web Intelligence), versions 4.1, 4.2, can access database with unencrypted connection, even if the quality of protection should be encrypted.

References (2)

Core 2
Core References
Permissions Required, Vendor Advisory x_refsource_misc
https://launchpad.support.sap.com/#/notes/2751470

Scores

CVSS v3 6.5
EPSS 0.0013
EPSS Percentile 31.3%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-319
Status published
Products (2)
sap/businessobjects_business_intelligence 4.1
sap/businessobjects_business_intelligence 4.2
Published Aug 14, 2019
Tracked Since Feb 18, 2026