CVE-2019-0352

HIGH

SAP BusinessObjects Business Intelligence Platform - Exposure of Sensitive Information via Cached Dynamic Pages

Title source: llm
STIX 2.1

Description

In SAP Business Objects Business Intelligence Platform, before versions 4.1, 4.2 and 4.3, some dynamic pages (like jsp) are cached, which leads to an attacker can see the sensitive information via cache and can open the dynamic pages even after logout.

References (2)

Core 2
Core References
Permissions Required, Vendor Advisory x_refsource_misc
https://launchpad.support.sap.com/#/notes/2735924

Scores

CVSS v3 7.5
EPSS 0.0028
EPSS Percentile 51.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-200
Status published
Products (3)
sap/businessobjects_business_intelligence_platform 4.10
sap/businessobjects_business_intelligence_platform 4.20
sap/businessobjects_business_intelligence_platform 4.30
Published Sep 10, 2019
Tracked Since Feb 18, 2026