Information Disclosure Vulnerability in SAP Business Objects by SAP
CVE-2019-0346
Key Information:
- Vendor
SAP
- Vendor
- CVE Published:
- 14 August 2019
What is CVE-2019-0346?
The vulnerability occurs due to an unencrypted communication issue within the Central Management Console of SAP Business Objects Business Intelligence Platform version 4.2. This flaw allows unauthorized access to sensitive data, specifically the disclosure of usernames and roles that have been imported from SAP NetWeaver BI systems. As a result, attackers may exploit this vulnerability to gain insights into user access levels and roles within the system, potentially leading to further misuse of sensitive information.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
SAP Business Objects Business Intelligence Platform (CMC) < 4.2
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved