CVE-2015-2076: Infoleak
Published Feb 27, 2015
·Updated
The Auditing service in SAP BusinessObjects Edge 4.0 allows remote attackers to obtain sensitive information by reading an audit event, aka SAP Note 2011395.
Affected Software
1 affected component
SAP BusinessObjects Edge=4.0
Event History
Feb 27, 2015
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-2076?
CVE-2015-2076 has a medium severity rating due to its potential for unauthorized access to sensitive audit information.
2
How do I fix CVE-2015-2076?
To fix CVE-2015-2076, apply the recommended patch as indicated in SAP Note 2011395.
3
What types of information can be accessed through CVE-2015-2076?
CVE-2015-2076 allows remote attackers to read sensitive audit event data, which can include confidential business information.
4
Which versions of SAP BusinessObjects are affected by CVE-2015-2076?
CVE-2015-2076 specifically affects SAP BusinessObjects Edge version 4.0.
5
Can CVE-2015-2076 be exploited remotely?
Yes, CVE-2015-2076 can be exploited remotely, allowing attackers to access sensitive information without physical access.