CVE-2019-0348Cleartext Transmission of Sensitive Info in SE SAP Business Objects Business Intelligence Platform

Severity
6.5MEDIUMNVD
EPSS
0.1%
top 68.08%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 14
Latest updateMay 24

Description

SAP BusinessObjects Business Intelligence Platform (Web Intelligence), versions 4.1, 4.2, can access database with unencrypted connection, even if the quality of protection should be encrypted.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NExploitability: 2.8 | Impact: 3.6

🔴Vulnerability Details

2
GHSA
GHSA-mxqq-vq68-78hq: SAP BusinessObjects Business Intelligence Platform (Web Intelligence), versions 42022-05-24
CVEList
CVE-2019-0348: SAP BusinessObjects Business Intelligence Platform (Web Intelligence), versions 42019-08-14

💬Community

1
Bugzilla
CVE-2019-7090 flash-plugin: Information Disclosure vulnerability (APSB19-06)2019-02-12
CVE-2019-0348 — MEDIUM severity | cvebase