PT-2023-15950 · Sap · Sap Businessobjects Business Intelligence Platform Cmc Application

Publicado

2023-01-10

·

Atualizado

2023-01-13

·

CVE-2023-0018

CVSS v3.1

10

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SAP BusinessObjects Business Intelligence Platform CMC application versions 420, and 430
Description The issue arises from improper input sanitization of user-controlled input in the SAP BusinessObjects Business Intelligence Platform CMC application. An attacker with basic user-level privileges can modify or upload crystal reports containing a malicious payload. Once these reports are viewable, anyone who opens them is susceptible to stored XSS attacks. As a result, information maintained in the victim's web browser can be read, modified, and sent to the attacker.
Recommendations For versions 420 and 430, consider disabling the ability to modify or upload crystal reports until a patch is available. Restrict access to the CMC application to minimize the risk of exploitation. Avoid using the application to view or open reports from untrusted sources until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-0018

Produtos afetados

Sap Businessobjects Business Intelligence Platform Cmc Application