Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

CVE-2019-0289 Information Disclosure in SAP BusinessObjects Business Intelligence platform / Analysis for OLAP, SAP security note 2738796

SAP Note 2738796

SAP security note 2738796, "[CVE-2019-0289] Information Disclosure in SAP BusinessObjects Business Intelligence platform / Analysis for OLAP". Below are the symptom, SAP recommended solution and the affected software components.

Description

Symptom

Under certain conditions, SAP BusinessObjects Business Intelligence platform / Analysis for OLAP allows an attacker to access information which would otherwise be restricted.

Some well-known impacts of Information Disclosure are:

  • Loss of information and system configuration confidentiality: Metadata
  • Information gathering for further exploits and attacks

Solution

The parameters are now correctly passed on connection, ensuring encryption.

This issue is fixed in the patches listed in the Support Packages & Patches section below.

For Business Intelligence Platform maintenance schedule and strategy, see Knowledge Base Article 2144559 in the References section.

Reason and prerequisites

Communication is not encrypted because the connection is not opened with the correct parameters.

CVSS

Score 5.4 Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N

Affected components

  • Business intelligence solutions > Reporting, analysis, and dashboards > Analysis, edition for OLAP (Web)

Full note on SAP: SAP Support Launchpad note 2738796

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More