First published: Wed Aug 14 2019(Updated: )
SAP BusinessObjects Business Intelligence Platform (Info View), versions 4.1, 4.2, 4.3, allows an attacker to give some payload for keyword in the search and it will be executed while search performs its action, resulting in Cross-Site Scripting (XSS) vulnerability.
Credit: cna@sap.com
Affected Software | Affected Version | How to fix |
---|---|---|
SAP BusinessObjects Business Intelligence | =4.1 | |
SAP BusinessObjects Business Intelligence | =4.2 | |
SAP BusinessObjects Business Intelligence | =4.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-0332 is a Cross-Site Scripting (XSS) vulnerability in SAP BusinessObjects Business Intelligence Platform (Info View) versions 4.1, 4.2, and 4.3.
CVE-2019-0332 has a severity rating of medium with a CVSS score of 6.1.
CVE-2019-0332 allows an attacker to execute a payload using the search functionality, leading to Cross-Site Scripting (XSS) attacks in SAP BusinessObjects Business Intelligence Platform.
CVE-2019-0332 affects SAP BusinessObjects Business Intelligence Platform versions 4.1, 4.2, and 4.3.
To mitigate CVE-2019-0332, it is recommended to apply the necessary patches or updates provided by SAP.