TROYANOSYVIRUS
Back to CVEs

CVE-2019-0352

HIGH
7.5

Description

In SAP Business Objects Business Intelligence Platform, before versions 4.1, 4.2 and 4.3, some dynamic pages (like jsp) are cached, which leads to an attacker can see the sensitive information via cache and can open the dynamic pages even after logout.

CVE Details

CVSS v3.1 Score7.5
SeverityHIGH
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Attack VectorNETWORK
ComplexityLOW
Privileges RequiredNONE
User InteractionNONE
Published9/10/2019
Last Modified11/21/2024
Sourcenvd
Honeypot Sightings0

Affected Products

sap:businessobjects_business_intelligence_platform

Weaknesses (CWE)

CWE-200

IOC Correlations

No correlations recorded

This product uses data from the NVD API but is not endorsed or certified by the NVD.