CVE Vulnerabilities

CVE-2018-2446

Published: Aug 14, 2018 | Modified: Nov 21, 2024
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Admin tools in SAP BusinessObjects Business Intelligence, versions 4.1, 4.2, allow an unauthenticated user to read sensitive information (server name), hence leading to an information disclosure.

Affected Software

NameVendorStart VersionEnd Version
Businessobjects_business_intelligenceSap4.1 (including)4.1 (including)
Businessobjects_business_intelligenceSap4.2 (including)4.2 (including)

References