PT-2023-15950 · Sap · Sap Businessobjects Business Intelligence Platform Cmc Application

Published

2023-01-10

·

Updated

2023-01-13

·

CVE-2023-0018

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SAP BusinessObjects Business Intelligence Platform CMC application versions 420, and 430
Description The issue arises from improper input sanitization of user-controlled input in the SAP BusinessObjects Business Intelligence Platform CMC application. An attacker with basic user-level privileges can modify or upload crystal reports containing a malicious payload. Once these reports are viewable, anyone who opens them is susceptible to stored XSS attacks. As a result, information maintained in the victim's web browser can be read, modified, and sent to the attacker.
Recommendations For versions 420 and 430, consider disabling the ability to modify or upload crystal reports until a patch is available. Restrict access to the CMC application to minimize the risk of exploitation. Avoid using the application to view or open reports from untrusted sources until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2023-0018

Affected Products

Sap Businessobjects Business Intelligence Platform Cmc Application