First published: Tue Oct 09 2018(Updated: )
SAP BusinessObjects Business Intelligence Platform 4.10 and 4.20 (Web Intelligence DHTML client) does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability.
Credit: cna@sap.com
Affected Software | Affected Version | How to fix |
---|---|---|
SAP BusinessObjects Business Intelligence | =4.1 | |
SAP BusinessObjects Business Intelligence | =4.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-2472 has a medium severity rating due to its potential to allow Cross-Site Scripting (XSS) attacks.
To fix CVE-2018-2472, update to the patched versions provided by SAP for BusinessObjects Business Intelligence Platform 4.1 and 4.2.
CVE-2018-2472 affects SAP BusinessObjects Business Intelligence Platform versions 4.1 and 4.2, specifically the Web Intelligence DHTML client.
CVE-2018-2472 may result in unauthorized access to user information through Cross-Site Scripting vulnerabilities.
As of now, there have been no reported active exploitations of CVE-2018-2472, but it remains a concern due to the nature of XSS vulnerabilities.