URL Manipulation Vulnerability in SAP BusinessObjects BI Platform by SAP
CVE-2018-2467
5.3MEDIUM
Key Information:
- Vendor
SAP
- Vendor
- CVE Published:
- 9 October 2018
What is CVE-2018-2467?
A vulnerability found in the Software Development Kit of SAP BusinessObjects BI Platform Servers, versions 4.1 and 4.2, allows an attacker to exploit a specially crafted URL. When accessed via a browser, such as Chrome, the system inadvertently exposes the path of the application server due to an internal error. This can lead to further exposure of system internals, potentially facilitating additional attacks.
Affected Version(s)
SAP BusinessObjects BI Platform Servers (Software Development Kit) 4.1
SAP BusinessObjects BI Platform Servers (Software Development Kit) 4.2