Unencrypted communication error in SAP Business Objects Business Intelligence Platform (Central Management Console), version 4.2, leads to disclosure of list of user names and roles imported from SAP NetWeaver BI systems, resulting in Information Disclosure.
References
Link | Resource |
---|---|
https://launchpad.support.sap.com/#/notes/2764513 | Permissions Required Vendor Advisory |
https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=523998017 | Vendor Advisory |
https://launchpad.support.sap.com/#/notes/2764513 | Permissions Required Vendor Advisory |
https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=523998017 | Vendor Advisory |
Configurations
History
21 Nov 2024, 04:16
Type | Values Removed | Values Added |
---|---|---|
References | () https://launchpad.support.sap.com/#/notes/2764513 - Permissions Required, Vendor Advisory | |
References | () https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=523998017 - Vendor Advisory |
Information
Published : 2019-08-14 14:15
Updated : 2024-11-21 04:16
NVD link : CVE-2019-0346
Mitre link : CVE-2019-0346
CVE.ORG link : CVE-2019-0346
JSON object : View
Products Affected
sap
- businessobjects_business_intelligence
CWE
CWE-319
Cleartext Transmission of Sensitive Information