Stored Cross Site Scripting in SAP BusinessObjects Business Intelligence Platform
CVE-2019-0395
5.4MEDIUM
Key Information:
- Vendor
SAP
- Vendor
- CVE Published:
- 11 December 2019
What is CVE-2019-0395?
The SAP BusinessObjects Business Intelligence Platform's Fiori BI Launchpad, prior to version 4.2, contains a security flaw that permits the execution of malicious JavaScript code within a text module. This vulnerability facilitates stored cross site scripting attacks, potentially allowing attackers to manipulate user sessions and steal sensitive data. Organizations utilizing vulnerable versions of this platform are urged to upgrade to mitigate the risks associated with this security issue.
Affected Version(s)
SAP BusinessObjects Business Intelligence Platform (Fiori BI Launchpad) before 4.2