Stored Cross Site Scripting in SAP BusinessObjects Business Intelligence Platform
CVE-2019-0395

5.4MEDIUM

Key Information:

Summary

The SAP BusinessObjects Business Intelligence Platform's Fiori BI Launchpad, prior to version 4.2, contains a security flaw that permits the execution of malicious JavaScript code within a text module. This vulnerability facilitates stored cross site scripting attacks, potentially allowing attackers to manipulate user sessions and steal sensitive data. Organizations utilizing vulnerable versions of this platform are urged to upgrade to mitigate the risks associated with this security issue.

Affected Version(s)

SAP BusinessObjects Business Intelligence Platform (Fiori BI Launchpad) before 4.2

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.