PT-2019-11234 · Sap · Sap Businessobjects Business Intelligence Platform

Published

2019-12-11

·

Updated

2019-12-17

·

CVE-2019-0398

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: SAP BusinessObjects Business Intelligence Platform (Monitoring Application) versions prior to 4.1 SAP BusinessObjects Business Intelligence Platform (Monitoring Application) versions prior to 4.2 SAP BusinessObjects Business Intelligence Platform (Monitoring Application) versions prior to 4.3
Description: The issue is due to insufficient CSRF protection, which may allow an authenticated user to send unintended requests to the web server, leading to Cross Site Request Forgery.
Recommendations: For versions prior to 4.1, update to version 4.1 or later. For versions prior to 4.2, update to version 4.2 or later. For versions prior to 4.3, update to version 4.3 or later.

Fix

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-0398

Affected Products

Sap Businessobjects Business Intelligence Platform