First published: Tue Dec 12 2017(Updated: )
Cross-Site Scripting (XSS) vulnerability in SAP Business Intelligence Promotion Management Application, Enterprise 4.10, 4.20, 4.30, as user controlled inputs are not sufficiently encoded.
Credit: cna@sap.com
Affected Software | Affected Version | How to fix |
---|---|---|
SAP BusinessObjects Business Intelligence | =4.10 | |
SAP BusinessObjects Business Intelligence | =4.20 | |
SAP BusinessObjects Business Intelligence | =4.30 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-16681 has a medium severity rating due to its potential for exploitation through cross-site scripting.
To fix CVE-2017-16681, ensure that proper encoding is applied to user inputs in the SAP Business Intelligence Promotion Management Application.
CVE-2017-16681 affects versions 4.10, 4.20, and 4.30 of the SAP Business Intelligence Promotion Management Application.
CVE-2017-16681 is a Cross-Site Scripting (XSS) vulnerability.
Yes, the XSS vulnerability in CVE-2017-16681 may allow attackers to steal sensitive information from users.