First published: Tue Oct 10 2023(Updated: )
SAP BusinessObjects Web Intelligence - version 420, has a URL with parameter that could be vulnerable to XSS attack. The attacker could send a malicious link to a user that would possibly allow an attacker to retrieve the sensitive information.
Credit: cna@sap.com cna@sap.com
Affected Software | Affected Version | How to fix |
---|---|---|
SAP BusinessObjects Web Intelligence | =420 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-42474 is a vulnerability in SAP BusinessObjects Web Intelligence version 420 that allows for a potential XSS attack through a URL parameter.
CVE-2023-42474 can potentially allow an attacker to send a malicious link to a user, enabling them to retrieve sensitive information.
The severity of CVE-2023-42474 is rated as medium with a CVSS score of 5.4.
To fix CVE-2023-42474, it is recommended to update SAP BusinessObjects Web Intelligence to a version that addresses the vulnerability.
You can find more information about CVE-2023-42474 in the SAP Notes (3372991) and the official SAP documentation.