URL Manipulation Vulnerability in SAP BusinessObjects BI Platform by SAP
CVE-2018-2467

5.3MEDIUM

What is CVE-2018-2467?

A vulnerability found in the Software Development Kit of SAP BusinessObjects BI Platform Servers, versions 4.1 and 4.2, allows an attacker to exploit a specially crafted URL. When accessed via a browser, such as Chrome, the system inadvertently exposes the path of the application server due to an internal error. This can lead to further exposure of system internals, potentially facilitating additional attacks.

Affected Version(s)

SAP BusinessObjects BI Platform Servers (Software Development Kit) 4.1

SAP BusinessObjects BI Platform Servers (Software Development Kit) 4.2

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2018-2467 : URL Manipulation Vulnerability in SAP BusinessObjects BI Platform by SAP