SAP security note 2654905, "[CVE-2018-2471] Information Disclosure in SAP BusinessObjects BI Suite". Below are the symptom and SAP recommended solution.
Description
Symptom
Under certain conditions, SAP BusinessObjects BI Suite allows an attacker to access information that would otherwise be restricted.
Loss of information and system configuration confidentiality.
Information gathering for further exploits and attacks.
Solution
User rights are now leveraged when running such queries in the Central Management Server. The issue has been fixed in the patches listed in the Support Packages & Patches section below. For Business Intelligence Platform maintenance schedule and strategy, see SAP Note 2144559.
CVSS
Score 9.8 / 10 Vector: AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
References
- CVE-2018-2471
Full note on SAP: SAP Support Launchpad note 2654905
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



