PT-2019-5657 · Sap · Sap Businessobjects Business Intelligence Platform

Publicado

2019-08-13

·

Atualizado

2019-08-22

·

CVE-2019-0334

CVSS v3.1

5.4

Média

VetorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions SAP BusinessObjects Business Intelligence Platform (BI Workspace) versions 4.1 through 4.3
Description The issue allows a malicious script to be stored in a module, potentially enabling a user to escalate privileges via session hijacking when the script is executed later. This could also lead to access of other sensitive information due to Stored Cross Site Scripting. The vulnerability exists due to inadequate protection of the web page structure, which may allow a remote attacker to elevate privileges or disclose protected information.
Recommendations For versions 4.1 through 4.3, consider disabling the module creation feature in BI Workspace until a patch is available to prevent the storage and execution of malicious scripts. Restrict access to sensitive information and monitor user sessions for potential hijacking attempts.

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2020-04841
CVE-2019-0334

Produtos afetados

Sap Businessobjects Business Intelligence Platform