First published: Tue Oct 08 2019(Updated: )
SAP BusinessObjects Business Intelligence Platform (Web Intelligence HTML interface), before versions 4.2 and 4.3, does not sufficiently encode user-controlled inputs and allows execution of scripts in the export dialog box of the report name resulting in reflected Cross-Site Scripting.
Credit: cna@sap.com
Affected Software | Affected Version | How to fix |
---|---|---|
Sap Businessobjects Business Intelligence Platform | =4.0 | |
Sap Businessobjects Business Intelligence Platform | =4.1 | |
Sap Businessobjects Business Intelligence Platform | =4.1-sp10 | |
Sap Businessobjects Business Intelligence Platform | =4.1-sp11 | |
Sap Businessobjects Business Intelligence Platform | =4.1-sp12 | |
Sap Businessobjects Business Intelligence Platform | =4.2-sp04 | |
Sap Businessobjects Business Intelligence Platform | =4.2-sp05 | |
Sap Businessobjects Business Intelligence Platform | =4.2-sp06 | |
Sap Businessobjects Business Intelligence Platform | =4.2-sp07 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of this issue is CVE-2019-0375.
The severity level of CVE-2019-0375 is medium.
The affected software of CVE-2019-0375 is SAP BusinessObjects Business Intelligence Platform versions 4.0 to 4.2.
CVE-2019-0375 allows execution of scripts in the export dialog box of the report name resulting in reflected Cross-Site Scripting.
Yes, you can find references for CVE-2019-0375 [here](https://launchpad.support.sap.com/#/notes/2817945) and [here](https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=528123050).