First published: Thu Jul 25 2019(Updated: )
Yellowfin Smart Reporting All Versions Prior to 7.3 is affected by: Incorrect Access Control - Privileges Escalation. The impact is: Victim attacked and access admin functionality through their browser and control browser. The component is: MIAdminStyles.i4. The attack vector is: Victims are typically lured to a web site under the attacker's control; the XSS vulnerability on the target domain is silently exploited without the victim's knowledge. The fixed version is: 7.4 and later.
Credit: josh@bress.net
Affected Software | Affected Version | How to fix |
---|---|---|
Bmc Remedy Smart Reporting | ||
Yellowfinbi Yellowfin Bi | <7.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2019-1010147.
The title of the vulnerability is Incorrect Access Control - Privileges Escalation in Yellowfin Smart Reporting.
The severity of CVE-2019-1010147 is medium with a CVSS score of 5.4.
CVE-2019-1010147 allows an attacker to access admin functionality through the victim's browser and gain control over the browser.
The affected component of CVE-2019-1010147 is MIAdminStyles.i4.
The attack vector of CVE-2019-1010147 is through typical victims.
All versions prior to 7.3 of Yellowfin Smart Reporting and BMC Remedy Smart Reporting are affected by CVE-2019-1010147.
It is recommended to upgrade Yellowfin Smart Reporting to version 7.3 or newer to fix CVE-2019-1010147.
The CWE ID of CVE-2019-1010147 is 79, which stands for Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting').
You can find more information about CVE-2019-1010147 at the following link: [https://drive.google.com/open?id=1sk5IklziyEggeWpWE4Wyk9xqa30CjNpS]