CVE-2019-0352
Summary
| CVE | CVE-2019-0352 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-09-10 17:15:00 UTC |
| Updated | 2019-09-11 12:20:00 UTC |
| Description | In SAP Business Objects Business Intelligence Platform, before versions 4.1, 4.2 and 4.3, some dynamic pages (like jsp) are cached, which leads to an attacker can see the sensitive information via cache and can open the dynamic pages even after logout. |
Risk And Classification
Problem Types: CWE-200
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Sap | Businessobjects Business Intelligence Platform | 4.10 | All | All | All |
| Application | Sap | Businessobjects Business Intelligence Platform | 4.20 | All | All | All |
| Application | Sap | Businessobjects Business Intelligence Platform | 4.30 | All | All | All |
| Application | Sap | Businessobjects Business Intelligence Platform | 4.10 | All | All | All |
| Application | Sap | Businessobjects Business Intelligence Platform | 4.20 | All | All | All |
| Application | Sap | Businessobjects Business Intelligence Platform | 4.30 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| launchpad.support.sap.com | MISC | launchpad.support.sap.com | Permissions Required, Vendor Advisory |
| SAP Security Patch Day – September 2019 - Product Security Response at SAP - SCN Wiki | CONFIRM | wiki.scn.sap.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.