Unencrypted communication error in SAP Business Objects Business Intelligence Platform (Central Management Console), version 4.2, leads to disclosure of list of user names and roles imported from SAP NetWeaver BI systems, resulting in Information Disclosure.
References
Link | Resource |
---|---|
https://launchpad.support.sap.com/#/notes/2764513 | Permissions Required Vendor Advisory |
https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=523998017 | Vendor Advisory |
Configurations
History
No history.
Information
Published : 2019-08-14 14:15
Updated : 2020-08-24 17:37
NVD link : CVE-2019-0346
Mitre link : CVE-2019-0346
CVE.ORG link : CVE-2019-0346
JSON object : View
Products Affected
sap
- businessobjects_business_intelligence
CWE
CWE-319
Cleartext Transmission of Sensitive Information