CVE-2018-2471 is a high-severity information disclosure vulnerability affecting SAP BusinessObjects Business Intelligence Platform versions 4.10 and 4.20, allowing unauthorized access to restricted information. With a CVSS score of 7.5, this vulnerability is network-exploitable with low attack complexity and no user interaction required, leading to a high impact on confidentiality. While no public exploit code or active exploitation has been observed, and it is not listed in CISA's KEV catalog, the vulnerability has garnered some community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
4.10CPE matchmatch criteria | cpe:2.3:a:sap:businessobjects_business_intelligence_platform:4.10:*:*:*:*:*:*:* | ||
4.20CPE matchmatch criteria | cpe:2.3:a:sap:businessobjects_business_intelligence_platform:4.20:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.