First published: Wed Aug 14 2019(Updated: )
Unencrypted communication error in SAP Business Objects Business Intelligence Platform (Central Management Console), version 4.2, leads to disclosure of list of user names and roles imported from SAP NetWeaver BI systems, resulting in Information Disclosure.
Credit: cna@sap.com
Affected Software | Affected Version | How to fix |
---|---|---|
SAP BusinessObjects Business Intelligence | =4.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability identifier for this SAP Business Objects vulnerability is CVE-2019-0346.
The affected software for this vulnerability is SAP BusinessObjects Business Intelligence Platform version 4.2.
The severity of the CVE-2019-0346 vulnerability is medium, with a CVSS score of 6.5.
The impact of the CVE-2019-0346 vulnerability is the disclosure of a list of user names and roles imported from SAP NetWeaver BI systems, resulting in information disclosure.
To fix the CVE-2019-0346 vulnerability, it is recommended to apply the necessary patches provided by SAP and ensure that communication is encrypted between the SAP Business Objects Business Intelligence Platform and SAP NetWeaver BI systems.