CVE-2019-0398

HIGH

SAP BusinessObjects Business Intelligence Platform - Cross-Site Request Forgery

Title source: llm
STIX 2.1

Description

Due to insufficient CSRF protection, SAP BusinessObjects Business Intelligence Platform (Monitoring Application), before versions 4.1, 4.2 and 4.3, may lead to an authenticated user to send unintended request to the web server, leading to Cross Site Request Forgery.

References (2)

Core 2
Core References
Permissions Required x_refsource_confirm
https://launchpad.support.sap.com/#/notes/2701027

Scores

CVSS v3 8.8
EPSS 0.0017
EPSS Percentile 37.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Details

CWE
CWE-352
Status published
Products (3)
sap/businessobjects_business_intelligence_platform 4.1
sap/businessobjects_business_intelligence_platform 4.2
sap/businessobjects_business_intelligence_platform 4.3
Published Dec 11, 2019
Tracked Since Feb 18, 2026