Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

CVE-2019-0269 Cross-Site Scripting (XSS) vulnerability in SAP BusinessObjects BIWorkspace, SAP security note 2693962

SAP Note 2693962

SAP security note 2693962, "CVE-2019-0269 XSS Vulnerability in SAP BusinessObjects BIWorkspace". Below are the symptom, SAP recommended solution and the affected software components.

Description

Symptom

A Cross-Site Scripting (XSS) vulnerability has been identified in SAP BusinessObjects BIWorkspace. The application fails to sufficiently encode user-controlled inputs, which can be exploited to execute malicious scripts.

  • Content Modification: Attackers can deface or modify displayed content on the affected website.
  • Authentication Theft: Sensitive authentication information, including session data, can be stolen.
  • User Impersonation: Attackers can impersonate users and access information with the same privileges as the targeted user.

Solution

This vulnerability is addressed in the patches listed under the "Support Packages & Patches" section of the SAP Security Note. It’s crucial to apply the relevant patches to mitigate the risk.

References

Affected components

  • SAP BusinessObjects Business Intelligence Platform 4.1
  • SAP BusinessObjects Business Intelligence Platform 4.2

Full note on SAP: SAP Support Launchpad note 2693962

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More