Cross-Site Scripting Vulnerability in SAP BusinessObjects BI Platform
CVE-2019-0326
Key Information:
- Vendor
- SAP
- Vendor
- CVE Published:
- 10 July 2019
Summary
The SAP BusinessObjects Business Intelligence Platform (BI Workspace) across versions 4.1, 4.2, and 4.3 contains a vulnerability that allows malicious actors to execute arbitrary scripts within the context of the user's session. This arises from insufficient encoding of user-controlled inputs, leading to potential exploitation through Cross-Site Scripting. Deploying necessary updates is crucial to mitigate risks associated with this flaw.
Affected Version(s)
SAP BusinessObjects Business Intelligence Platform - BI Workspace (Enterprise) < 4.1 < 4.1
SAP BusinessObjects Business Intelligence Platform - BI Workspace (Enterprise) < 4.2 < 4.2
SAP BusinessObjects Business Intelligence Platform - BI Workspace (Enterprise) < 4.3 < 4.3
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved