CVE-2019-0352
Last modified
CVE-2019-0352 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. In SAP Business Objects Business Intelligence Platform, before versions 4.1, 4.2 and 4.3, some dynamic pages (like jsp) are cached, which leads to an attacker can see the sensitive information via cache and can open the dynamic pages even after logout.. EPSS estimates a 1.08% chance of exploitation in the next 30 days.
Description
In SAP Business Objects Business Intelligence Platform, before versions 4.1, 4.2 and 4.3, some dynamic pages (like jsp) are cached, which leads to an attacker can see the sensitive information via cache and can open the dynamic pages even after logout.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Sap | Businessobjects Business Intelligence Platform | 4.10 |
| Sap | Businessobjects Business Intelligence Platform | 4.20 |
| Sap | Businessobjects Business Intelligence Platform | 4.30 |
References
- https://launchpad.support.sap.com/#/notes/2735924Permissions Required, Vendor Advisory
- https://launchpad.support.sap.com/#/notes/2735924Permissions Required, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2019-0352?
How severe is CVE-2019-0352?
How do I fix CVE-2019-0352?
Are you affected by CVE-2019-0352?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
