Medium priority
SAP security note 2623618, "[CVE-2018-2467] File Path Disclosure in SAP Business Intelligence Software Development Kit", was released on October 9, 2018. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
A vulnerability was identified in SAP BusinessObjects BI Platform Servers (versions 4.1 and 4.2) where using a specially crafted URL in a web browser such as Chrome could cause the system to return an error displaying the file path of the application server. This information disclosure can lead to:
- Loss of information and system configuration confidentiality
- Information gathering for further exploits and attacks
Solution
The issue has been addressed by SAP by handling the error within the application and providing a standard error message to users. This fix is available in the relevant support packages.
CVSS
Score 5.3/10 Vector: AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Affected components
- SAP BusinessObjects BI Platform Servers (4.1 and 4.2)
Full note on SAP: SAP Support Launchpad note 2623618
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



