CVE-2019-0377: XSS
SAP BusinessObjects Business Intelligence Platform (Web Intelligence HTML interface), before versions 4.2, does not sufficiently encode user-controlled inputs and allows an attacker to store malicious scripts in the input controls, resulting in Stored Cross-Site Scripting.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-0377?
CVE-2019-0377 is classified as a medium severity vulnerability due to its potential for Stored Cross-Site Scripting exploitation.
How do I fix CVE-2019-0377?
To fix CVE-2019-0377, upgrade to SAP BusinessObjects Business Intelligence Platform version 4.2 or later.
What type of vulnerability is CVE-2019-0377?
CVE-2019-0377 is a Stored Cross-Site Scripting (XSS) vulnerability that allows attackers to store malicious scripts.
Which SAP versions are affected by CVE-2019-0377?
Versions 4.0 and 4.1 of SAP BusinessObjects Business Intelligence Platform are affected by CVE-2019-0377.
What is the impact of CVE-2019-0377?
The impact of CVE-2019-0377 includes unauthorized script execution within user-controlled inputs, potentially compromising user sessions.