CVE-2019-0352Sensitive Information Exposure in SE SAP Businessobjects Business Intelligence Platform

Severity
7.5HIGHNVD
EPSS
0.3%
top 48.51%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 10
Latest updateMay 24

Description

In SAP Business Objects Business Intelligence Platform, before versions 4.1, 4.2 and 4.3, some dynamic pages (like jsp) are cached, which leads to an attacker can see the sensitive information via cache and can open the dynamic pages even after logout.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 3.9 | Impact: 3.6

🔴Vulnerability Details

2
GHSA
GHSA-5873-j2gq-266m: In SAP Business Objects Business Intelligence Platform, before versions 42022-05-24
CVEList
CVE-2019-0352: In SAP Business Objects Business Intelligence Platform, before versions 42019-09-10
CVE-2019-0352 — Sensitive Information Exposure | cvebase