High severity7.5NVD Advisory· Published Jan 8, 2019· Updated Jun 17, 2026
CVE-2018-2499
CVE-2018-2499
Description
A security weakness in SAP Financial Consolidation Cube Designer (BOBJ_EADES fixed in versions 8.0, 10.1) may allow an attacker to discover the password hash of an admin user.
Affected products
4cpe:2.3:a:sap:financial_consolidation_cube_designer:10.1:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:sap:financial_consolidation_cube_designer:10.1:*:*:*:*:*:*:*
- (no CPE)range: 8.0, 10.1
- cpe:2.3:a:sap:financial_consolidation_cube_designer_bobj_eades:8.0:*:*:*:*:*:*:*
- SAP SE/SAP Financial Consolidation Cube Designer (BOBJ_EADES)v5Range: < 8.0
Patches
Vulnerability mechanics
References
3- www.securityfocus.com/bid/106466nvdThird Party AdvisoryVDB Entry
- launchpad.support.sap.comnvdPermissions RequiredVendor Advisory
- wiki.scn.sap.com/wiki/pages/viewpage.actionnvdVendor Advisory
News mentions
0No linked articles in our index yet.