CVE-2008-1894: XSS
Cross-site scripting (XSS) vulnerability in desktoplaunch/InfoView/logon/logon.object in BusinessObjects InfoView XI R2 SP1, SP2, and SP3 Java version before FixPack 3.5 allows remote attackers to inject arbitrary web script or HTML via the cms parameter.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2008-1894?
CVE-2008-1894 has a medium severity level due to its potential for Cross-site Scripting (XSS) attacks.
How do I fix CVE-2008-1894?
To fix CVE-2008-1894, upgrade to BusinessObjects InfoView XI R2 Fix Pack 3.5 or later.
What products are affected by CVE-2008-1894?
CVE-2008-1894 affects various versions of SAP BusinessObjects InfoView XI R2, specifically SP1, SP2, and SP3 before Fix Pack 3.5.
What kind of attack can CVE-2008-1894 enable?
CVE-2008-1894 enables remote attackers to inject arbitrary web scripts or HTML into the affected application.
Is CVE-2008-1894 still a concern today?
While CVE-2008-1894 has been addressed in updated versions, it remains a concern for any systems that have not been patched.