First published: Tue Feb 14 2023(Updated: )
In SAP BusinessObjects Business Intelligence (Web Intelligence user interface) - version 430, some calls return json with wrong content type in the header of the response. As a result, a custom application that calls directly the jsp of Web Intelligence DHTML may be vulnerable to XSS attacks. On successful exploitation an attacker can cause a low impact on integrity of the application.
Credit: cna@sap.com
Affected Software | Affected Version | How to fix |
---|---|---|
SAP Business Objects Business Intelligence Platform | =430 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-23856 is a vulnerability in SAP BusinessObjects Business Intelligence (Web Intelligence user interface) version 430 that could allow XSS attacks.
CVE-2023-23856 has a severity rating of medium, with a score of 5.4.
CVE-2023-23856 can be exploited through XSS attacks on custom applications that call the jsp of Web Intelligence DHTML.
Yes, SAP has provided a fix for CVE-2023-23856. It is recommended to update to the latest version of SAP BusinessObjects Business Intelligence (Web Intelligence user interface).
You can find more information about CVE-2023-23856 on SAP's official website and the SAP Support Portal.