Stored Cross Site Scripting Vulnerability in SAP BusinessObjects Business Intelligence Platform
CVE-2019-0334
5.4MEDIUM
Key Information:
- Vendor
- SAP
- Vendor
- CVE Published:
- 14 August 2019
Summary
A vulnerability in SAP BusinessObjects Business Intelligence Platform allows the creation of a module that can store malicious scripts. When these scripts are executed, they may let attackers escalate privileges through session hijacking. Furthermore, this flaw exposes sensitive information, potentially leading to Stored Cross Site Scripting attacks, undermining the security of affected systems.
Affected Version(s)
SAP BusinessObjects Business Intelligence Platform (BI Workspace) < 4.1 < 4.1
SAP BusinessObjects Business Intelligence Platform (BI Workspace) < 4.2 < 4.2
SAP BusinessObjects Business Intelligence Platform (BI Workspace) < 4.3 < 4.3
References
CVSS V3.1
Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved