CVE-2019-0374: XSS
SAP BusinessObjects Business Intelligence Platform (Web Intelligence HTML interface), before versions 4.2 and 4.3, does not sufficiently encode user-controlled inputs and allows execution of scripts in the chart title resulting in reflected Cross-Site Scripting
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2019-0374.
What is the severity of CVE-2019-0374?
The severity of CVE-2019-0374 is medium.
Which SAP BusinessObjects versions are affected by CVE-2019-0374?
SAP BusinessObjects Business Intelligence Platform versions 4.0, 4.1, 4.1 SP10, 4.1 SP11, 4.1 SP12, 4.2 SP04, 4.2 SP05, 4.2 SP06, and 4.2 SP07 are affected by CVE-2019-0374.
How can the vulnerability be exploited?
The vulnerability can be exploited by executing scripts in the chart title resulting in reflected Cross-Site Scripting (XSS).
How can I fix CVE-2019-0374?
To fix CVE-2019-0374, apply the necessary patches provided by SAP BusinessObjects Business Intelligence Platform.