CVE-2018-2467 is a medium-severity information disclosure vulnerability affecting SAP BusinessObjects BI Platform Servers versions 4.1 and 4.2. An unauthenticated attacker can craft a specific URL to trigger an error message that reveals the application server's path, potentially aiding further reconnaissance. The CVSS score is 5.3, indicating low impact on confidentiality and no impact on integrity or availability. There is no evidence of active exploitation, public exploit code, or Metasploit/Nuclei modules, though it has received some community and media attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
4.1CPE matchmatch criteria | cpe:2.3:a:sap:businessobjects_bi_platform:4.1:*:*:*:*:*:*:* | ||
4.2CPE matchmatch criteria | cpe:2.3:a:sap:businessobjects_bi_platform:4.2:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.