Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

CVE-2018-2483 HTTP Verb Tampering vulnerability in SAP BI CMC, SAP security note 2647714

SAP Note 2647714
Medium priority

SAP security note 2647714, "[CVE-2018-2483] HTTP Verb Tampering vulnerability in SAP BI CMC", is a program error note released on November 13, 2018. Below are the symptom and the affected software components.

CategoryProgram error
PriorityMedium priority
StatusReleased for Customer
Released onNovember 13, 2018
LanguageEnglish

Description

Symptom

SAP has released this security note addressing a HTTP Verb Tampering vulnerability in the SAP Business Intelligence Central Management Console (CMC). This vulnerability allows an attacker to manipulate request methods, potentially impacting the security of the BI platform.

CVSS

Score 4.3/10 Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Affected components

  • ENTERPRISE (410, 420)

Full note on SAP: SAP Support Launchpad note 2647714

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More