CVE Vulnerabilities

CVE-2018-2445

Server-Side Request Forgery (SSRF)

Published: Aug 14, 2018 | Modified: Oct 15, 2018
CVSS 3.x
9.6
CRITICAL
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N
CVSS 2.x
5.5 MEDIUM
AV:N/AC:L/Au:S/C:P/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu

AdminTools in SAP BusinessObjects Business Intelligence, versions 4.1, 4.2, allows an attacker to manipulate the vulnerable application to send crafted requests on behalf of the application, resulting in a Server-Side Request Forgery (SSRF) vulnerability.

Weakness

The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.

Affected Software

Name Vendor Start Version End Version
Businessobjects_business_intelligence Sap 4.1 (including) 4.1 (including)
Businessobjects_business_intelligence Sap 4.2 (including) 4.2 (including)

References