First published: Wed Nov 13 2019(Updated: )
SAP BusinessObjects Business Intelligence Platform (Web Intelligence HTML interface), corrected in versions 4.1 and 4.2, does not sufficiently validate an XML document accepted from an untrusted source. An attacker can craft a message that contains malicious elements that will not be correctly filtered by Web Intelligence HTML interface in some specific workflows.
Credit: cna@sap.com
Affected Software | Affected Version | How to fix |
---|---|---|
Sap Businessobjects Business Intelligence Platform | =4.0 | |
Sap Businessobjects Business Intelligence Platform | =4.1-sp10 | |
Sap Businessobjects Business Intelligence Platform | =4.1-sp11 | |
Sap Businessobjects Business Intelligence Platform | =4.1-sp12 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-0396 is a vulnerability in SAP BusinessObjects Business Intelligence Platform (Web Intelligence HTML interface) that allows an attacker to craft a malicious XML document to execute arbitrary code.
CVE-2019-0396 has a severity rating of 7.1 (High).
CVE-2019-0396 affects versions 4.0, 4.1-SP10, 4.1-SP11, and 4.1-SP12 of SAP BusinessObjects Business Intelligence Platform.
To fix CVE-2019-0396, users should upgrade to versions 4.1 or 4.2 of SAP BusinessObjects Business Intelligence Platform.
More information about CVE-2019-0396 can be found on the SAP Support Portal (Note 2814007) and the SAP Community Wiki.