CVE-2019-0376: XSS
SAP BusinessObjects Business Intelligence Platform (Web Intelligence HTML interface), before versions 4.2 and 4.3, does not sufficiently encode user-controlled inputs and allows an attacker to save malicious scripts in the publication name, which can be executed later by the victim, resulting in Stored Cross-Site Scripting.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of this SAP BusinessObjects Business Intelligence Platform vulnerability?
The vulnerability ID is CVE-2019-0376.
What is the severity rating of CVE-2019-0376?
The severity rating of CVE-2019-0376 is medium with a CVSS score of 5.4.
What versions of SAP BusinessObjects Business Intelligence Platform are affected by CVE-2019-0376?
Versions 4.0, 4.1, 4.1-sp10, 4.1-sp11, 4.1-sp12, 4.2-sp04, 4.2-sp05, 4.2-sp06, and 4.2-sp07 of SAP BusinessObjects Business Intelligence Platform are affected by CVE-2019-0376.
How does CVE-2019-0376 impact the SAP BusinessObjects Business Intelligence Platform?
CVE-2019-0376 allows an attacker to save malicious scripts in the publication name, which can be executed later by the victim.
Are there any official references for CVE-2019-0376?
Yes, you can find official references for CVE-2019-0376 at the following links: [SAP Note 2817945](https://launchpad.support.sap.com/#/notes/2817945) and [SAP SCN Wiki](https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=528123050).