ZeroHour

CVE-2019-0333

CVSS 3.0
6.5 medium
EPSS
1%p65
Published
()
Modified
Description

In some situations, when a client cancels a query in SAP BusinessObjects Business Intelligence Platform (Web Intelligence), versions 4.2, 4.3, the attacker can then query and receive the whole data set instead of just what is part of their authorized security profile, resulting in Information Disclosure.

Vendors
sap
Products
businessobjects business intelligence
Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.