CVE-2023-0018: Cross-Site Scripting (XSS) vulnerability in SAP BusinessObjects Business Intelligence Platform (Central management console)
Due to improper input sanitization of user-controlled input in SAP BusinessObjects Business Intelligence Platform CMC application - versions 420, and 430, an attacker with basic user-level privileges can modify/upload crystal reports containing a malicious payload. Once these reports are viewable, anyone who opens those reports would be susceptible to stored XSS attacks. As a result of the attack, information maintained in the victim's web browser can be read, modified, and sent to the attacker.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-0018?
CVE-2023-0018 is a vulnerability in SAP BusinessObjects Business Intelligence Platform CMC application versions 420 and 430.
What is the severity of CVE-2023-0018?
CVE-2023-0018 has a severity rating of 6.1, which is considered critical.
How does CVE-2023-0018 affect SAP BusinessObjects Business Intelligence Platform?
CVE-2023-0018 allows an attacker with basic user-level privileges to modify/upload crystal reports containing a malicious payload in SAP BusinessObjects Business Intelligence Platform CMC application versions 420 and 430.
How can an attacker exploit CVE-2023-0018?
An attacker can exploit CVE-2023-0018 by uploading crystal reports with a malicious payload, which can be viewed by users with access to SAP BusinessObjects Business Intelligence Platform CMC application versions 420 and 430.
Are there any fixes or patches available for CVE-2023-0018?
Yes, SAP has released patches to address CVE-2023-0018. Please refer to the SAP Security Note 3266006 for more information.