CVE-2019-0262: XSS
Published Feb 15, 2019
·Updated
SAP WebIntelligence BILaunchPad, versions 4.10, 4.20, does not sufficiently encode user-controlled inputs in generated HTML reports, resulting in Cross-Site Scripting (XSS) vulnerability.
Affected Software
2 affected components
SAP BusinessObjects BI Platform=4.10
SAP BusinessObjects BI Platform=4.20
Event History
Feb 15, 2019
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2019-0262?
CVE-2019-0262 has been classified as a medium severity vulnerability due to its potential to exploit Cross-Site Scripting (XSS) in affected versions.
2
How do I fix CVE-2019-0262?
To mitigate CVE-2019-0262, users should apply the latest patches provided by SAP for the BusinessObjects BI Platform versions 4.10 and 4.20.
3
What versions are affected by CVE-2019-0262?
CVE-2019-0262 affects SAP BusinessObjects BI Platform versions 4.10 and 4.20.
4
What type of vulnerability is CVE-2019-0262?
CVE-2019-0262 is classified as a Cross-Site Scripting (XSS) vulnerability.
5
Can CVE-2019-0262 be exploited remotely?
Yes, CVE-2019-0262 can be exploited remotely, allowing attackers to inject malicious scripts into generated HTML reports.