PT-2019-11231 · Sap · Sap Businessobjects Business Intelligence Platform
Published
2019-08-14
·
Updated
2020-08-24
·
CVE-2019-0348
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions:
SAP BusinessObjects Business Intelligence Platform (Web Intelligence) versions 4.1, 4.2
Description:
The issue allows access to a database with an unencrypted connection, despite the quality of protection being set to encrypted.
Recommendations:
For versions 4.1 and 4.2, consider configuring the database connection to enforce encrypted connections to prevent unauthorized access.
Fix
Cleartext Transmission of Sensitive Information
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sap Businessobjects Business Intelligence Platform