PT-2019-4460 · Sap · Sap Businessobjects Business Intelligence Platform

Published

2019-11-12

·

Updated

2019-11-15

·

CVE-2019-0396

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:S/C:P/I:N/A:C
Name of the Vulnerable Software and Affected Versions SAP BusinessObjects Business Intelligence Platform versions prior to 4.1 SAP BusinessObjects Business Intelligence Platform version 4.2 is not affected by this issue as it is mentioned to be corrected in versions 4.1 and 4.2, implying version 4.2 is a fixed version.
Description The issue arises due to insufficient validation of an XML document accepted from an untrusted source by the Web Intelligence HTML interface in the SAP BusinessObjects Business Intelligence Platform. This can be exploited by an attacker crafting a message with malicious elements that are not correctly filtered in specific workflows, potentially impacting the confidentiality and availability of protected information.
Recommendations For versions prior to 4.1, update to version 4.1 or later to resolve the issue. As a temporary workaround, consider restricting the acceptance of XML documents from untrusted sources until a patch is applied.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2020-00247
CVE-2019-0396

Affected Products

Sap Businessobjects Business Intelligence Platform