SAP security note 2817945, "[CVE-2019-0374] Multiple Cross-Site Scripting (XSS) vulnerabilities in SAP BusinessObjects Business Intelligence Platform (Web Intelligence HTML interface)". Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
SAP BusinessObjects Business Intelligence Platform (Web Intelligence HTML interface) has multiple Cross-Site Scripting (XSS) vulnerabilities. These vulnerabilities result from insufficient encoding of user-controlled inputs, leading to both reflected and stored XSS attacks. Attackers can exploit these to:
- Deface or modify displayed content
- Steal user authentication information or session data
- Impersonate the user and access information with the same privileges
Solution
User inputs are now properly encoded in the affected workflows. Apply the relevant patches as listed below.
CVSS
Score 5.4 Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
References
Affected components
- WebI designer
- Document controls
- Various other generic locations within the platform
Full note on SAP: SAP Support Launchpad note 2817945
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
