CVE-2022-39800
MEDIUMSAP BusinessObjects Business Intelligence LaunchPad 420, 430 - Unauthenticated Cross-Site Scripting
Title source: llmDescription
SAP BusinessObjects BI LaunchPad - versions 420, 430, is susceptible to script execution attack by an unauthenticated attacker due to improper sanitization of the user inputs while interacting on the network. On successful exploitation, an attacker can view or modify information causing a limited impact on confidentiality and integrity of the application.
References (2)
Core 2
Core References
Permissions Required, Vendor Advisory
https://launchpad.support.sap.com/#/notes/3211161
Scores
CVSS v3
6.1
EPSS
0.0180
EPSS Percentile
83.0%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Details
CWE
CWE-79
Status
published
Products (2)
sap/businessobjects_business_intelligence
420
sap/businessobjects_business_intelligence
430
Published
Oct 11, 2022
Tracked Since
Feb 18, 2026