CVE-2019-0334: XSS
When creating a module in SAP BusinessObjects Business Intelligence Platform (BI Workspace), versions 4.1, 4.2, 4.3, it is possible to store a malicious script which when executed later could potentially allow a user to escalate privileges via session hijacking. The attacker could also access other sensitive information, leading to Stored Cross Site Scripting.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-0334?
The severity of CVE-2019-0334 is medium.
How can an attacker exploit CVE-2019-0334?
An attacker can exploit CVE-2019-0334 by storing a malicious script that, when executed, could allow session hijacking and privilege escalation.
Which versions of SAP BusinessObjects Business Intelligence are affected by CVE-2019-0334?
Versions 4.1, 4.2, and 4.3 of SAP BusinessObjects Business Intelligence are affected by CVE-2019-0334.
How can I mitigate the vulnerability in CVE-2019-0334?
To mitigate CVE-2019-0334, apply the necessary patches provided by SAP and follow their recommended security guidelines.
Where can I find more information about CVE-2019-0334?
You can find more information about CVE-2019-0334 in the SAP Support Portal and the SAP Community Network.