Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

CVE-2018-2446 Information disclosure vulnerability in BI Query Builder, SAP security note 2633846

SAP Note 2633846

SAP security note 2633846, "[CVE-2018-2446] Information disclosure vulnerability in BI Query Builder". Below are the symptom, SAP recommended solution and the affected software components.

Description

Symptom

SAP Business Objects Business Intelligence admin tools allow an unauthenticated user to read sensitive information (server name), leading to an information disclosure.

Impacts of Information Disclosure:

  • Loss of information and system configuration confidentiality
  • Information gathering for further exploits and attacks

Solution

The issue has been fixed in the patches listed in the "Support Package Patches" section below. For Business Intelligence Platform maintenance schedule and strategy, see the Knowledge Base Article 2144559 in the References section.

Reason and prerequisites

The server name is displayed in an unauthorized way which is unexpected.

CVSS

Score 5.3 Vector: AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

References

Affected components

  • ENTERPRISE 410 to 410
  • ENTERPRISE 420 to 420

Full note on SAP: SAP Support Launchpad note 2633846

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More