CVE-2014-8308: XSS
Published Oct 16, 2014
·Updated
Cross-site scripting (XSS) vulnerability in the Send to Inbox functionality in SAP BusinessObjects BI EDGE 4.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Affected Software
1 affected component
SAP BusinessObjects=4.0
Event History
Oct 16, 2014
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-8308?
CVE-2014-8308 is classified as a medium-severity vulnerability due to its potential for cross-site scripting attacks.
2
How do I fix CVE-2014-8308?
To remediate CVE-2014-8308, upgrading to a patched version of SAP BusinessObjects BI EDGE beyond 4.0 is recommended.
3
What types of attacks can CVE-2014-8308 enable?
CVE-2014-8308 can enable remote attackers to inject arbitrary web scripts or HTML into the application.
4
Which versions of SAP BusinessObjects are affected by CVE-2014-8308?
CVE-2014-8308 specifically affects SAP BusinessObjects BI EDGE version 4.0.
5
Can CVE-2014-8308 be exploited remotely?
Yes, CVE-2014-8308 can be exploited remotely, allowing attackers to leverage the Send to Inbox functionality.