CVE-2019-0398: CSRF
Due to insufficient CSRF protection, SAP BusinessObjects Business Intelligence Platform (Monitoring Application), before versions 4.1, 4.2 and 4.3, may lead to an authenticated user to send unintended request to the web server, leading to Cross Site Request Forgery.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-0398?
CVE-2019-0398 is a vulnerability in SAP BusinessObjects Business Intelligence Platform that may lead to Cross Site Request Forgery.
What is the severity of CVE-2019-0398?
CVE-2019-0398 has a severity rating of 8.8 (High).
Which versions of SAP BusinessObjects Business Intelligence Platform are affected by CVE-2019-0398?
Versions 4.1, 4.2, and 4.3 of SAP BusinessObjects Business Intelligence Platform are affected by CVE-2019-0398.
How can an authenticated user exploit CVE-2019-0398?
An authenticated user can exploit CVE-2019-0398 by sending unintended requests to the web server, leading to Cross Site Request Forgery.
How can I fix CVE-2019-0398?
To fix CVE-2019-0398, it is recommended to upgrade to a patched version of SAP BusinessObjects Business Intelligence Platform.