7.5
CVSSv3

CVE-2018-2499

Published: 08/01/2019 Updated: 24/08/2020
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

A security weakness in SAP Financial Consolidation Cube Designer (BOBJ_EADES fixed in versions 8.0, 10.1) may allow an malicious user to discover the password hash of an admin user.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

sap financial consolidation cube designer 10.1

sap financial consolidation cube designer bobj eades 8.0

Recent Articles

Make a SAP decision: Apply these security fixes if you're using German giant's software
The Register • Richard Chirgwin • 09 Jan 2019

11 patches ship on Patch Tuesday

While you were sighing your way through Microsoft's Patch Tuesday, enterprise vendor SAP slid 11 security advisories under your door. Top of the list is a depressingly familiar howler in SAP Cloud Connector pre-version 2.11.3: the software neglects authentication checks for functions that require user identity (CVE-2019-0246). A related bug in Cloud Connector (the same versions), CVE-2019-0247, can be exploited to achieve remote code injection. The German titan's systems management environment, ...