CVE-2018-2446: High severity sap businessobjects business intelligence platform vulnerability
Published Aug 14, 2018
·Updated
Admin tools in SAP BusinessObjects Business Intelligence, versions 4.1, 4.2, allow an unauthenticated user to read sensitive information (server name), hence leading to an information disclosure.
Affected Software
2 affected components
SAP BusinessObjects Business Intelligence=4.1
SAP BusinessObjects Business Intelligence=4.2
Event History
Aug 14, 2018
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2018-2446.
2
What is the severity of CVE-2018-2446?
The severity of CVE-2018-2446 is high with a CVSS score of 7.5.
3
Which software versions are affected by CVE-2018-2446?
SAP BusinessObjects Business Intelligence versions 4.1 and 4.2 are affected by CVE-2018-2446.
4
What is the impact of CVE-2018-2446?
CVE-2018-2446 allows an unauthenticated user to read sensitive information (server name), leading to an information disclosure.
5
How can I mitigate CVE-2018-2446?
To mitigate CVE-2018-2446, you should apply the necessary patches provided by SAP.