CVE-2023-23856: XSS
In SAP BusinessObjects Business Intelligence (Web Intelligence user interface) - version 430, some calls return json with wrong content type in the header of the response. As a result, a custom application that calls directly the jsp of Web Intelligence DHTML may be vulnerable to XSS attacks. On successful exploitation an attacker can cause a low impact on integrity of the application.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-23856?
CVE-2023-23856 is a vulnerability in SAP BusinessObjects Business Intelligence (Web Intelligence user interface) version 430 that could allow XSS attacks.
What is the severity of CVE-2023-23856?
CVE-2023-23856 has a severity rating of medium, with a score of 5.4.
How can CVE-2023-23856 be exploited?
CVE-2023-23856 can be exploited through XSS attacks on custom applications that call the jsp of Web Intelligence DHTML.
Is there a fix available for CVE-2023-23856?
Yes, SAP has provided a fix for CVE-2023-23856. It is recommended to update to the latest version of SAP BusinessObjects Business Intelligence (Web Intelligence user interface).
Where can I find more information about CVE-2023-23856?
You can find more information about CVE-2023-23856 on SAP's official website and the SAP Support Portal.