Stored Cross-Site Scripting Vulnerability in SAP BusinessObjects BI Platform
CVE-2019-0377
5.4MEDIUM
Key Information:
- Vendor
SAP
- Vendor
- CVE Published:
- 8 October 2019
What is CVE-2019-0377?
The SAP BusinessObjects Business Intelligence Platform's Web Intelligence HTML interface prior to version 4.2 lacks adequate encoding for user-controlled inputs. This weakness allows attackers to inject malicious scripts, leading to Stored Cross-Site Scripting (XSS). Such vulnerabilities can compromise web applications and user data, making it essential for organizations to apply patches or updates to safeguard their systems.
Affected Version(s)
SAP BusinessObjects Business Intelligence Platform (Web Intelligence HTML interface) < 4.2