First published: Tue Oct 08 2019(Updated: )
SAP BusinessObjects Business Intelligence Platform (Web Intelligence HTML interface), before versions 4.2, does not sufficiently encode user-controlled inputs and allows an attacker to store malicious scripts in the input controls, resulting in Stored Cross-Site Scripting.
Credit: cna@sap.com
Affected Software | Affected Version | How to fix |
---|---|---|
Sap Businessobjects Business Intelligence Platform | =4.0 | |
Sap Businessobjects Business Intelligence Platform | =4.1 | |
Sap Businessobjects Business Intelligence Platform | =4.1-sp10 | |
Sap Businessobjects Business Intelligence Platform | =4.1-sp11 | |
Sap Businessobjects Business Intelligence Platform | =4.1-sp12 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.