First published: Tue Dec 10 2019(Updated: )
A cross-site scripting (XSS) vulnerability exists when Microsoft SQL Server Reporting Services (SSRS) does not properly sanitize a specially-crafted web request to an affected SSRS server, aka 'Microsoft SQL Server Reporting Services XSS Vulnerability'.
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Power BI Report Server | ||
Microsoft Sql Server 2017 Reporting Services | ||
Microsoft Sql Server 2019 Reporting Services |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The CVE ID of this vulnerability is CVE-2019-1332.
The severity rating of CVE-2019-1332 is medium (6.1).
The vulnerability affects Microsoft SQL Server Reporting Services by allowing a specially-crafted web request to execute cross-site scripting (XSS) attacks.
The following software versions are affected by CVE-2019-1332: Microsoft Power BI Report Server, Microsoft SQL Server 2017 Reporting Services, and Microsoft SQL Server 2019 Reporting Services.
To fix CVE-2019-1332, it is recommended to apply the latest security update provided by Microsoft.