CVE-2018-2432: XSS
SAP BusinessObjects Business Intelligence (BI Launchpad and Central Management Console) versions 4.10, 4.20 and 4.30 allow an attacker to include invalidated data in the HTTP response header sent to a Web user. Successful exploitation of this vulnerability may lead to advanced attacks, including: cross-site scripting and page hijacking.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the vulnerability ID for this vulnerability?
The vulnerability ID is CVE-2018-2432.
What is the title of this vulnerability?
The title of this vulnerability is SAP BusinessObjects Business Intelligence (BI Launchpad and Central Management Console) versions 4.1...
What is the severity level of CVE-2018-2432?
The severity level of CVE-2018-2432 is medium (5.4).
Which versions of SAP BusinessObjects Business Intelligence are affected by this vulnerability?
Versions 4.10, 4.20, and 4.30 of SAP BusinessObjects Business Intelligence are affected by this vulnerability.
How can an attacker exploit this vulnerability?
An attacker can exploit this vulnerability by including invalidated data in the HTTP response header sent to a Web user.