CVE-2018-2447

CWE-89SQL Injection3 documents3 sources
Severity
6.5MEDIUM
EPSS
0.4%
top 39.77%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 14
Latest updateMay 14

Description

SAP BusinessObjects Business Intelligence (Launchpad Web Intelligence), version 4.2, allows an attacker to execute crafted InfoObject queries, exposing the CMS InfoObjects database.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NExploitability: 2.8 | Impact: 3.6

🔴Vulnerability Details

2
GHSA
GHSA-mrv3-h573-pvqg: SAP BusinessObjects Business Intelligence (Launchpad Web Intelligence), version 42022-05-14
CVEList
CVE-2018-2447: SAP BusinessObjects Business Intelligence (Launchpad Web Intelligence), version 42018-08-14