First published: Tue Sep 10 2019(Updated: )
In SAP Business Objects Business Intelligence Platform, before versions 4.1, 4.2 and 4.3, some dynamic pages (like jsp) are cached, which leads to an attacker can see the sensitive information via cache and can open the dynamic pages even after logout.
Credit: cna@sap.com
Affected Software | Affected Version | How to fix |
---|---|---|
Sap Businessobjects Business Intelligence Platform | =4.10 | |
Sap Businessobjects Business Intelligence Platform | =4.20 | |
Sap Businessobjects Business Intelligence Platform | =4.30 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-0352 has a medium severity rating due to the risk of exposing sensitive information through cached pages.
To fix CVE-2019-0352, you should upgrade your SAP Business Objects Business Intelligence Platform to version 4.1, 4.2, or 4.3.
CVE-2019-0352 can allow unauthorized users to access sensitive information that is cached in dynamic pages.
Yes, CVE-2019-0352 can be exploited remotely by attackers to access cached pages containing sensitive data.
CVE-2019-0352 affects SAP Business Objects Business Intelligence Platform versions 4.10, 4.20, and 4.30.