First published: Tue Jul 10 2018(Updated: )
SAP BusinessObjects Business Intelligence (BI Launchpad and Central Management Console) versions 4.10, 4.20 and 4.30 allow an attacker to include invalidated data in the HTTP response header sent to a Web user. Successful exploitation of this vulnerability may lead to advanced attacks, including: cross-site scripting and page hijacking.
Credit: cna@sap.com
Affected Software | Affected Version | How to fix |
---|---|---|
SAP BusinessObjects Business Intelligence | =4.1 | |
SAP BusinessObjects Business Intelligence | =4.2 | |
SAP BusinessObjects Business Intelligence | =4.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2018-2432.
The title of this vulnerability is SAP BusinessObjects Business Intelligence (BI Launchpad and Central Management Console) versions 4.1...
The severity level of CVE-2018-2432 is medium (5.4).
Versions 4.10, 4.20, and 4.30 of SAP BusinessObjects Business Intelligence are affected by this vulnerability.
An attacker can exploit this vulnerability by including invalidated data in the HTTP response header sent to a Web user.