First published: Tue Mar 12 2019(Updated: )
SAP BusinessObjects Business Intelligence Platform (CMC Module), versions 4.10, 4.20 and 4.30, does not sufficiently validate an XML document accepted from an untrusted source.
Credit: cna@sap.com
Affected Software | Affected Version | How to fix |
---|---|---|
SAP BusinessObjects Business Intelligence | =4.1 | |
SAP BusinessObjects Business Intelligence | =4.2 | |
SAP BusinessObjects Business Intelligence | =4.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2019-0268 is high.
Versions 4.10, 4.20, and 4.30 of SAP BusinessObjects Business Intelligence Platform (CMC Module) are affected by CVE-2019-0268.
CVE-2019-0268 allows an attacker to execute arbitrary XML External Entity (XXE) attacks, leading to information disclosure and other attacks.
You can find more information about CVE-2019-0268 on the following references: [Link 1](http://www.securityfocus.com/bid/107364), [Link 2](https://launchpad.support.sap.com/#/notes/2689259), [Link 3](https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=515408080).
To fix CVE-2019-0268, apply the relevant security patches provided by SAP and follow their recommended mitigation steps.