CVE-2019-0332

MEDIUM

SAP BusinessObjects Business Intelligence Platform 4.1-4.3 - Cross-Site Scripting via Info View Search Keyword

Title source: llm
STIX 2.1

Description

SAP BusinessObjects Business Intelligence Platform (Info View), versions 4.1, 4.2, 4.3, allows an attacker to give some payload for keyword in the search and it will be executed while search performs its action, resulting in Cross-Site Scripting (XSS) vulnerability.

References (2)

Core 2
Core References
Permissions Required, Vendor Advisory x_refsource_misc
https://launchpad.support.sap.com/#/notes/2742468

Scores

CVSS v3 6.1
EPSS 0.0023
EPSS Percentile 45.8%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Details

CWE
CWE-79
Status published
Products (3)
sap/businessobjects_business_intelligence 4.1
sap/businessobjects_business_intelligence 4.2
sap/businessobjects_business_intelligence 4.3
Published Aug 14, 2019
Tracked Since Feb 18, 2026