First published: Wed Dec 11 2019(Updated: )
SAP BusinessObjects Business Intelligence Platform (Fiori BI Launchpad), before version 4.2, allows execution of JavaScript in a text module in Fiori BI Launchpad, leading to Stored Cross Site Scripting vulnerability.
Credit: cna@sap.com
Affected Software | Affected Version | How to fix |
---|---|---|
Sap Businessobjects Business Intelligence Platform | <4.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of this issue is CVE-2019-0395.
CVE-2019-0395 has a severity rating of medium.
The affected software is SAP BusinessObjects Business Intelligence Platform (Fiori BI Launchpad), before version 4.2.
CVE-2019-0395 occurs due to the execution of JavaScript in a text module in Fiori BI Launchpad, leading to a Stored Cross Site Scripting vulnerability.
Yes, patches and fixes are available for CVE-2019-0395. It is recommended to update to version 4.2 or higher of SAP BusinessObjects Business Intelligence Platform (Fiori BI Launchpad).