First published: Wed Mar 14 2018(Updated: )
In SAP Business Objects Business Intelligence Platform, 4.00, 4.10, 4.20, 4.30, the Central Management Console (CMC) does not sufficiently encode user controlled inputs which results in Cross-Site Scripting.
Credit: cna@sap.com
Affected Software | Affected Version | How to fix |
---|---|---|
SAP BusinessObjects BI Platform | =4.00 | |
SAP BusinessObjects BI Platform | =4.10 | |
SAP BusinessObjects BI Platform | =4.20 | |
SAP BusinessObjects BI Platform | =4.30 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-2397 is classified as a medium severity vulnerability.
To fix CVE-2018-2397, apply the latest security updates provided by SAP for Business Intelligence Platform.
CVE-2018-2397 is a Cross-Site Scripting (XSS) vulnerability.
CVE-2018-2397 affects SAP Business Objects Business Intelligence Platform versions 4.00, 4.10, 4.20, and 4.30.
CVE-2018-2397 exploits insufficient encoding of user-controlled inputs in the Central Management Console.