First published: Tue Oct 08 2019(Updated: )
SAP BusinessObjects Business Intelligence Platform (Web Intelligence HTML interface), before versions 4.2 and 4.3, does not sufficiently encode user-controlled inputs and allows execution of scripts in the chart title resulting in reflected Cross-Site Scripting
Credit: cna@sap.com
Affected Software | Affected Version | How to fix |
---|---|---|
Sap Businessobjects Business Intelligence Platform | =4.0 | |
Sap Businessobjects Business Intelligence Platform | =4.1 | |
Sap Businessobjects Business Intelligence Platform | =4.1-sp10 | |
Sap Businessobjects Business Intelligence Platform | =4.1-sp11 | |
Sap Businessobjects Business Intelligence Platform | =4.1-sp12 | |
Sap Businessobjects Business Intelligence Platform | =4.2-sp04 | |
Sap Businessobjects Business Intelligence Platform | =4.2-sp05 | |
Sap Businessobjects Business Intelligence Platform | =4.2-sp06 | |
Sap Businessobjects Business Intelligence Platform | =4.2-sp07 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2019-0374.
The severity of CVE-2019-0374 is medium.
SAP BusinessObjects Business Intelligence Platform versions 4.0, 4.1, 4.1 SP10, 4.1 SP11, 4.1 SP12, 4.2 SP04, 4.2 SP05, 4.2 SP06, and 4.2 SP07 are affected by CVE-2019-0374.
The vulnerability can be exploited by executing scripts in the chart title resulting in reflected Cross-Site Scripting (XSS).
To fix CVE-2019-0374, apply the necessary patches provided by SAP BusinessObjects Business Intelligence Platform.