First published: Tue Aug 14 2018(Updated: )
SAP BusinessObjects Financial Consolidation, versions 10.0, 10.1, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability.
Credit: cna@sap.com
Affected Software | Affected Version | How to fix |
---|---|---|
SAP BusinessObjects Financial Consolidation | =10.0 | |
SAP BusinessObjects Financial Consolidation | =10.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-2444 is classified as a medium severity vulnerability due to the risk of XSS attacks.
To fix CVE-2018-2444, ensure that your SAP BusinessObjects Financial Consolidation is updated to a version that properly encodes user inputs.
CVE-2018-2444 can facilitate Cross-Site Scripting (XSS) attacks, allowing attackers to inject malicious scripts.
CVE-2018-2444 affects SAP BusinessObjects Financial Consolidation versions 10.0 and 10.1.
Yes, proper user input validation is crucial to mitigate the risks posed by the XSS vulnerability in CVE-2018-2444.