CVE-2018-2499: SAP Financial Consolidation Cube Designer

High severity, CVSS 7.5. EPSS: 1.7% chance of exploitation in the next 30 days.

A security weakness in SAP Financial Consolidation Cube Designer (BOBJ_EADES fixed in versions 8.0, 10.1) may allow an attacker to discover the password hash of an admin user.

Affected products

  • SAP Financial Consolidation Cube Designer: version 10.1 only
  • SAP Financial Consolidation Cube Designer Bobj Eades: version 8.0 only

Published 2019-01-08. Last modified 2026-06-17.