Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

CVE-2019-0352 Improper session management in SAP Business Objects Business Intelligence Platform(CMC), SAP security note 2735924

SAP Note 2735924

SAP security note 2735924, "[CVE-2019-0352] Improper session management in SAP Business Objects Business Intelligence Platform (CMC)", is a note. Below are the symptom and SAP recommended solution.

Description

Symptom

UPDATE 12th May 2020: This security note has been updated. For more detailed information, see Security Note 2878555 – Update 1 to Security Note 2735924 – [CVE-2019-0352] Improper session management in SAP Business Objects Business Intelligence Platform (CMC).

In SAP Business Objects Business Intelligence Platform, there are spots where dynamic pages (like JSP) are cached. Due to this, even after logout, an attacker can see sensitive information via the cache and can open the dynamic pages.

Solution

Cache has been disabled in dynamic pages wherever it’s not managed well.

This issue is fixed in the patches listed in the "Support Packages & Patches" section below. The "Support Packages & Patches" section will be populated with the relevant patch levels once they are released. For Business Intelligence Platform maintenance schedule and strategy, see Knowledge Base Article 2144559 in the References section.

CVSS

Score 4.3 Vector: CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

References

Full note on SAP: SAP Support Launchpad note 2735924

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More