PT-2010-5213 · Sap · Sap Businessobjects Enterprise Xi
Published
2010-10-18
·
Updated
2010-11-03
·
CVE-2010-3981
CVSS v2.0
4.3
Medium
| Vector | AV:N/AC:M/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
SAP BusinessObjects Enterprise XI version 3.2
Description
The issue is related to a cross-site scripting (XSS) vulnerability. This vulnerability allows remote attackers to inject arbitrary web script or HTML via the
ServiceClass field to the "Edit Service Parameters" page.Recommendations
For SAP BusinessObjects Enterprise XI version 3.2, update the software to a version that includes a fix for this issue, or consider restricting access to the Edit Service Parameters page as a temporary mitigation measure.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sap Businessobjects Enterprise Xi