Information Disclosure Vulnerability in SAP BusinessObjects Business Intelligence Platform
CVE-2019-0331
5.3MEDIUM
Key Information:
- Vendor
- SAP
- Vendor
- CVE Published:
- 14 August 2019
Summary
The SAP BusinessObjects Business Intelligence Platform, specifically the BI Workspace in versions 4.1, 4.2, and 4.3, is prone to an information disclosure vulnerability. This flaw could potentially allow an unauthorized attacker to gain access to sensitive information, such as the directory structure of the server. This may expose critical data to malicious actors, necessitating prompt steps for mitigation to protect sensitive information from unintended disclosure.
Affected Version(s)
SAP BusinessObjects Business Intelligence Platform (BI Workspace) < 4.1 < 4.1
SAP BusinessObjects Business Intelligence Platform (BI Workspace) < 4.2 < 4.2
SAP BusinessObjects Business Intelligence Platform (BI Workspace) < 4.3 < 4.3
References
CVSS V3.1
Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved