PT-2023-15949 · Sap · Sap Businessobjects Business Intelligence Platform

Published

2023-01-10

·

Updated

2023-01-13

·

CVE-2023-0015

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions SAP BusinessObjects Business Intelligence Platform version 420
Description The issue arises from some calls returning json with the wrong content type in the header of the response. This can make a custom application that directly calls the jsp of Web Intelligence DHTML vulnerable to XSS attacks. Successful exploitation can lead to limited impact on the confidentiality and integrity of the application.
Recommendations For version 420, update the software to a version that correctly sets the content type in the response header to prevent XSS attacks. As a temporary workaround, consider restricting direct access to the jsp of Web Intelligence DHTML to minimize the risk of exploitation.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2023-0015

Affected Products

Sap Businessobjects Business Intelligence Platform