First published: Tue May 14 2024(Updated: )
SAP Business Objects Business Intelligence Platform is vulnerable to stored XSS allowing an attacker to manipulate a parameter in the Opendocument URL which could lead to high impact on Confidentiality and Integrity of the application
Credit: cna@sap.com
Affected Software | Affected Version | How to fix |
---|---|---|
Sap Businessobjects Business Intelligence Platform |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-28165 has a high severity as it allows stored XSS which can threaten the confidentiality and integrity of the SAP Business Objects Business Intelligence Platform.
To fix CVE-2024-28165, apply the latest security patches provided by SAP for the Business Objects Business Intelligence Platform.
The risks associated with CVE-2024-28165 include potential unauthorized access to sensitive data and manipulation of application functionality through XSS attacks.
CVE-2024-28165 affects the SAP BusinessObjects Business Intelligence Platform due to its vulnerability to stored XSS.
Organizations using the SAP Business Objects Business Intelligence Platform can be affected by CVE-2024-28165 due to the stored XSS vulnerability.