First published: Wed Aug 14 2019(Updated: )
SAP BusinessObjects Business Intelligence Platform (Web Intelligence), versions 4.1, 4.2, can access database with unencrypted connection, even if the quality of protection should be encrypted.
Credit: cna@sap.com
Affected Software | Affected Version | How to fix |
---|---|---|
SAP BusinessObjects Business Intelligence Platform | =4.1 | |
SAP BusinessObjects Business Intelligence Platform | =4.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-0348 is considered a moderate severity vulnerability due to the potential exposure of sensitive data.
To fix CVE-2019-0348, ensure that the database connections are configured to use encrypted communication.
CVE-2019-0348 affects SAP BusinessObjects Business Intelligence Platform versions 4.1 and 4.2.
CVE-2019-0348 is an information disclosure vulnerability related to unencrypted database connections.
The primary risk of CVE-2019-0348 is unauthorized access to sensitive data being transmitted over unencrypted connections.