Exploit/Advisories Cybersecurity study of the dark web exposes vulnerability to machine identities -- ScienceDaily

Published on May 15th, 2019 📆 | 7541 Views ⚑

0

SAP Business Intelligence Platform 4.2/4.3 privilege escalation


Convert Text to Speech

CVSS Meta Temp Score Current Exploit Price (≈)
5.5 $5k-$25k

A vulnerability, which was classified as critical, has been found in SAP Business Intelligence Platform 4.2/4.3 (Business Process Management Software). Affected by this issue is some functionality. The manipulation with an unknown input leads to a privilege escalation vulnerability. Using CWE to declare the problem leads to CWE-269. Impacted is confidentiality, integrity, and availability. CVE summarizes:

Under certain conditions SAP BusinessObjects Business Intelligence platform (Analysis for OLAP), versions 4.2 and 4.3, allows an attacker to access information which would otherwise be restricted.

The weakness was published 05/14/2019. This vulnerability is handled as CVE-2019-0289 since 11/26/2018. There are neither technical details nor an exploit publicly available. The current price for an exploit might be approx. USD $5k-$25k (estimation calculated on 05/15/2019).

There is no information about possible countermeasures known. It may be suggested to replace the affected object with an alternative product.

Similar entries are available at 135019.

Vendor

Name

VulDB Meta Base Score: 5.5
VulDB Meta Temp Score: 5.5

VulDB Base Score: ≈5.5
VulDB Temp Score: ≈5.5
VulDB Vector: ?
VulDB Reliability: ?





VulDB Base Score: ?
VulDB Temp Score: ?
VulDB Reliability: ?
Class: Privilege escalation (CWE-269)
Local: Yes
Remote: No

Availability: ?
Status: Not defined

Price Prediction: ?
Current Price Estimation: ?


0-Day unlock unlock unlock unlock
Today unlock unlock unlock unlock

Threat Intelligenceinfoedit

Threat: ?
Adversaries: ?
Geopolitics: ?
Economy: ?
Predictions: ?
Remediation: ?Recommended: no mitigation known
0-Day Time: ?11/26/2018 CVE assigned
05/14/2019 +169 days Advisory disclosed
05/15/2019 +1 days VulDB entry created
05/15/2019 +0 days VulDB last updateCVE: CVE-2019-0289 (?)
scip Labs: https://www.scip.ch/en/?labs.20150716
See also: ?Created: 05/15/2019 10:15 AM
Complete: ?

Download it now for free!

https://vuldb.com/?id.135020

Tagged with:



Comments are closed.