CVE-2019-0303: XSS
SAP BusinessObjects Business Intelligence Platform (Administration Console), versions 4.2, 4.3, module BILogon/appService.jsp is reflecting requested parameter errMsg into response content without sanitation. This could be used by an attacker to build a special url that execute custom JavaScript code when the url is accessed.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this SAP BusinessObjects vulnerability?
The vulnerability ID is CVE-2019-0303.
What is the title of this vulnerability?
The title of this vulnerability is 'SAP BusinessObjects Business Intelligence Platform (Administration Console) versions 4.2 4.3 module <module> reflects requested parameter errMsg into response content without sanitation.'
What versions of SAP BusinessObjects are affected by this vulnerability?
Versions 4.2 and 4.3 of SAP BusinessObjects are affected.
What is the severity of CVE-2019-0303?
The severity of CVE-2019-0303 is medium with a severity score of 6.1.
How can an attacker exploit this vulnerability?
An attacker can exploit this vulnerability by building a special URL that executes custom JavaScript code.
Is there a fix available for this vulnerability?
Yes, please refer to the SAP Notes and Wiki provided in the references section for information on available fixes.