PT-2019-4407 · Sap · Sap Businessobjects Business Intelligence Platform
Publicado
2019-11-12
·
Atualizado
2019-11-15
·
CVE-2019-0382
CVSS v2.0
5.5
Média
| Vetor | AV:N/AC:L/Au:S/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
SAP BusinessObjects Business Intelligence Platform (Web Intelligence) versions prior to 4.2
Description
The issue is related to the lack of protection of the web page structure in the Web Intelligence component of the SAP BusinessObjects Business Intelligence platform. This allows a remote attacker to perform cross-site scripting (XSS) attacks. The exploitation of this issue requires privileges.
Recommendations
For versions prior to 4.2, update to version 4.2 to resolve the issue. As a temporary workaround, consider restricting access to the Web Intelligence component to minimize the risk of exploitation.
Correção
XSS
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Sap Businessobjects Business Intelligence Platform