CVE-2022-39800

MEDIUM

SAP BusinessObjects Business Intelligence LaunchPad 420, 430 - Unauthenticated Cross-Site Scripting

Title source: llm
STIX 2.1

Description

SAP BusinessObjects BI LaunchPad - versions 420, 430, is susceptible to script execution attack by an unauthenticated attacker due to improper sanitization of the user inputs while interacting on the network. On successful exploitation, an attacker can view or modify information causing a limited impact on confidentiality and integrity of the application.

References (2)

Core 2

Scores

CVSS v3 6.1
EPSS 0.0180
EPSS Percentile 83.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Details

CWE
CWE-79
Status published
Products (2)
sap/businessobjects_business_intelligence 420
sap/businessobjects_business_intelligence 430
Published Oct 11, 2022
Tracked Since Feb 18, 2026