CVE-2019-0333Sensitive Information Exposure in SE SAP Businessobjects Business Intelligence Platform

3 documents3 sources
Severity
6.5MEDIUMNVD
EPSS
0.3%
top 49.47%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 14
Latest updateMay 24

Description

In some situations, when a client cancels a query in SAP BusinessObjects Business Intelligence Platform (Web Intelligence), versions 4.2, 4.3, the attacker can then query and receive the whole data set instead of just what is part of their authorized security profile, resulting in Information Disclosure.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NExploitability: 2.8 | Impact: 3.6

🔴Vulnerability Details

2
GHSA
GHSA-7345-wwch-f7q7: In some situations, when a client cancels a query in SAP BusinessObjects Business Intelligence Platform (Web Intelligence), versions 42022-05-24
CVEList
CVE-2019-0333: In some situations, when a client cancels a query in SAP BusinessObjects Business Intelligence Platform (Web Intelligence), versions 42019-08-14
CVE-2019-0333 — Sensitive Information Exposure | cvebase