High severity7.5NVD Advisory· Published Aug 14, 2018· Updated Jun 17, 2026
CVE-2018-2446
CVE-2018-2446
Description
Admin tools in SAP BusinessObjects Business Intelligence, versions 4.1, 4.2, allow an unauthenticated user to read sensitive information (server name), hence leading to an information disclosure.
Affected products
4cpe:2.3:a:sap:businessobjects_business_intelligence:4.1:-:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:sap:businessobjects_business_intelligence:4.1:-:*:*:*:*:*:*
- cpe:2.3:a:sap:businessobjects_business_intelligence:4.2:-:*:*:*:*:*:*
4.1, 4.2+ 1 more
- (no CPE)range: 4.1, 4.2
- (no CPE)range: 4.1
Patches
Vulnerability mechanics
References
3- www.securityfocus.com/bid/105089nvdThird Party AdvisoryVDB Entry
- launchpad.support.sap.comnvdPermissions RequiredVendor Advisory
- wiki.scn.sap.com/wiki/pages/viewpage.actionnvdVendor Advisory
News mentions
0No linked articles in our index yet.