CVE-2019-0375: XSS
SAP BusinessObjects Business Intelligence Platform (Web Intelligence HTML interface), before versions 4.2 and 4.3, does not sufficiently encode user-controlled inputs and allows execution of scripts in the export dialog box of the report name resulting in reflected Cross-Site Scripting.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of this issue?
The vulnerability ID of this issue is CVE-2019-0375.
What is the severity level of CVE-2019-0375?
The severity level of CVE-2019-0375 is medium.
What is the affected software of CVE-2019-0375?
The affected software of CVE-2019-0375 is SAP BusinessObjects Business Intelligence Platform versions 4.0 to 4.2.
How does CVE-2019-0375 impact the system?
CVE-2019-0375 allows execution of scripts in the export dialog box of the report name resulting in reflected Cross-Site Scripting.
Are there any references available for CVE-2019-0375?
Yes, you can find references for CVE-2019-0375 [here](https://launchpad.support.sap.com/#/notes/2817945) and [here](https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=528123050).