First published: Tue Nov 13 2018(Updated: )
HTTP Verb Tampering is possible in SAP BusinessObjects Business Intelligence Platform, versions 4.1 and 4.2, Central Management Console (CMC) by changing request method.
Credit: cna@sap.com
Affected Software | Affected Version | How to fix |
---|---|---|
SAP BusinessObjects Business Intelligence | =4.1 | |
SAP BusinessObjects Business Intelligence | =4.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2018-2483.
The severity of CVE-2018-2483 is medium with a CVSS score of 4.3.
The affected software for CVE-2018-2483 is SAP BusinessObjects Business Intelligence Platform versions 4.1 and 4.2.
HTTP Verb Tampering in SAP BusinessObjects Business Intelligence Platform versions 4.1 and 4.2 occurs by changing the request method in the Central Management Console (CMC).
More information about CVE-2018-2483 can be found at the following references: [1] http://www.securityfocus.com/bid/105899 [2] https://launchpad.support.sap.com/#/notes/2647714 [3] https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=503809832