CVE-2019-1332: XSS
A cross-site scripting (XSS) vulnerability exists when Microsoft SQL Server Reporting Services (SSRS) does not properly sanitize a specially-crafted web request to an affected SSRS server, aka 'Microsoft SQL Server Reporting Services XSS Vulnerability'.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the CVE ID of this vulnerability?
The CVE ID of this vulnerability is CVE-2019-1332.
What is the severity rating of CVE-2019-1332?
The severity rating of CVE-2019-1332 is medium (6.1).
How does the vulnerability affect Microsoft SQL Server Reporting Services?
The vulnerability affects Microsoft SQL Server Reporting Services by allowing a specially-crafted web request to execute cross-site scripting (XSS) attacks.
Which software versions are affected by CVE-2019-1332?
The following software versions are affected by CVE-2019-1332: Microsoft Power BI Report Server, Microsoft SQL Server 2017 Reporting Services, and Microsoft SQL Server 2019 Reporting Services.
How can I fix CVE-2019-1332?
To fix CVE-2019-1332, it is recommended to apply the latest security update provided by Microsoft.