PT-2023-28363 · Sap · Sap Businessobjects Business Intelligence Platform

Published

2023-12-11

·

Updated

2023-12-13

·

CVE-2023-42478

CVSS v3.1

7.6

High

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:H/A:N
Name of the Vulnerable Software and Affected Versions SAP Business Objects Business Intelligence Platform (affected versions not specified)
Description The issue allows an attacker to upload agnostic documents in the system, which when opened by any other user, could lead to a high impact on the integrity of the application due to stored XSS.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

XSS

Weakness Enumeration

Related Identifiers

CVE-2023-42478

Affected Products

Sap Businessobjects Business Intelligence Platform