Reflected Cross-Site Scripting in SAP BusinessObjects Business Intelligence Platform
CVE-2019-0374
5.4MEDIUM
Key Information:
- Vendor
- SAP
- Vendor
- CVE Published:
- 8 October 2019
Summary
The SAP BusinessObjects Business Intelligence Platform, specifically the Web Intelligence HTML interface in versions prior to 4.2 and 4.3, is susceptible to reflected Cross-Site Scripting attacks. This vulnerability arises from inadequate encoding of user inputs in the chart title feature, allowing attackers to inject malicious scripts. When a victim interacts with the compromised chart, these scripts can execute in their browser, leading to potential data exposure or further exploits.
Affected Version(s)
SAP BusinessObjects Business Intelligence Platform (Web Intelligence HTML interface) < 4.2 < 4.2
SAP BusinessObjects Business Intelligence Platform (Web Intelligence HTML interface) < 4.3 < 4.3
References
CVSS V3.1
Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved