CVE-2018-2472: XSS
SAP BusinessObjects Business Intelligence Platform 4.10 and 4.20 (Web Intelligence DHTML client) does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-2472?
CVE-2018-2472 has a medium severity rating due to its potential to allow Cross-Site Scripting (XSS) attacks.
How do I fix CVE-2018-2472?
To fix CVE-2018-2472, update to the patched versions provided by SAP for BusinessObjects Business Intelligence Platform 4.1 and 4.2.
What software is affected by CVE-2018-2472?
CVE-2018-2472 affects SAP BusinessObjects Business Intelligence Platform versions 4.1 and 4.2, specifically the Web Intelligence DHTML client.
What are the potential impacts of CVE-2018-2472?
CVE-2018-2472 may result in unauthorized access to user information through Cross-Site Scripting vulnerabilities.
Is CVE-2018-2472 being actively exploited?
As of now, there have been no reported active exploitations of CVE-2018-2472, but it remains a concern due to the nature of XSS vulnerabilities.