CVE-2023-31406: Cross-Site Scripting (XSS) vulnerability in SAP BusinessObjects Business Intelligence Platform
Due to insufficient input validation, SAP BusinessObjects Business Intelligence Platform - versions 420, 430, allows an unauthenticated attacker to redirect users to untrusted site using a malicious link. On successful exploitation, an attacker can view or modify information causing a limited impact on confidentiality and integrity of the application.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of this vulnerability?
The vulnerability ID is CVE-2023-31406.
What is the title of this vulnerability?
The title of this vulnerability is "Due to insufficient input validation SAP BusinessObjects Business Intelligence Platform - versions 420, 430."
What is the severity of CVE-2023-31406?
The severity of CVE-2023-31406 is medium.
How does CVE-2023-31406 impact the affected software?
CVE-2023-31406 allows an unauthenticated attacker to redirect users to an untrusted site using a malicious link, leading to a limited impact.
How can I fix CVE-2023-31406?
To fix CVE-2023-31406, it is recommended to apply the necessary patches or updates provided by SAP.