First published: Wed Dec 11 2019(Updated: )
Due to insufficient CSRF protection, SAP BusinessObjects Business Intelligence Platform (Monitoring Application), before versions 4.1, 4.2 and 4.3, may lead to an authenticated user to send unintended request to the web server, leading to Cross Site Request Forgery.
Credit: cna@sap.com
Affected Software | Affected Version | How to fix |
---|---|---|
Sap Businessobjects Business Intelligence Platform | =4.1 | |
Sap Businessobjects Business Intelligence Platform | =4.2 | |
Sap Businessobjects Business Intelligence Platform | =4.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-0398 is a vulnerability in SAP BusinessObjects Business Intelligence Platform that may lead to Cross Site Request Forgery.
CVE-2019-0398 has a severity rating of 8.8 (High).
Versions 4.1, 4.2, and 4.3 of SAP BusinessObjects Business Intelligence Platform are affected by CVE-2019-0398.
An authenticated user can exploit CVE-2019-0398 by sending unintended requests to the web server, leading to Cross Site Request Forgery.
To fix CVE-2019-0398, it is recommended to upgrade to a patched version of SAP BusinessObjects Business Intelligence Platform.