CVE-2019-0259: SAP Businessobjects

Critical severity, CVSS 9.8. EPSS: 2% chance of exploitation in the next 30 days.

SAP BusinessObjects, versions 4.2 and 4.3, (Visual Difference) allows an attacker to upload any file (including script files) without proper file format validation.

Affected products

  • SAP Businessobjects: version 4.2 only; version 4.3 only

Published 2019-02-15. Last modified 2026-06-17.