Stored Cross Site Scripting Vulnerability in SAP BusinessObjects Business Intelligence Platform
CVE-2019-0334

5.4MEDIUM

Key Information:

Vendor
SAP
Vendor
CVE Published:
14 August 2019

Summary

A vulnerability in SAP BusinessObjects Business Intelligence Platform allows the creation of a module that can store malicious scripts. When these scripts are executed, they may let attackers escalate privileges through session hijacking. Furthermore, this flaw exposes sensitive information, potentially leading to Stored Cross Site Scripting attacks, undermining the security of affected systems.

Affected Version(s)

SAP BusinessObjects Business Intelligence Platform (BI Workspace) < 4.1 < 4.1

SAP BusinessObjects Business Intelligence Platform (BI Workspace) < 4.2 < 4.2

SAP BusinessObjects Business Intelligence Platform (BI Workspace) < 4.3 < 4.3

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.