Reflected Cross-Site Scripting in SAP BusinessObjects Business Intelligence Platform
CVE-2019-0374
5.4MEDIUM
Key Information:
- Vendor
SAP
- Vendor
- CVE Published:
- 8 October 2019
What is CVE-2019-0374?
The SAP BusinessObjects Business Intelligence Platform, specifically the Web Intelligence HTML interface in versions prior to 4.2 and 4.3, is susceptible to reflected Cross-Site Scripting attacks. This vulnerability arises from inadequate encoding of user inputs in the chart title feature, allowing attackers to inject malicious scripts. When a victim interacts with the compromised chart, these scripts can execute in their browser, leading to potential data exposure or further exploits.
Affected Version(s)
SAP BusinessObjects Business Intelligence Platform (Web Intelligence HTML interface) < 4.2 < 4.2
SAP BusinessObjects Business Intelligence Platform (Web Intelligence HTML interface) < 4.3 < 4.3