Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

CVE-2019-0382 XSS vulnerabilty in SAP Business Objects BI Platform (Web Intelligence), SAP security note 2817937

SAP Note 2817937

SAP security note 2817937, "CVE-2019-0382: XSS Vulnerability in SAP Business Objects BI Platform (Web Intelligence)". Below are the symptom and SAP recommended solution.

Description

Symptom

SAP has released Security Note 2817937 addressing a Cross-Site Scripting (XSS) vulnerability in the SAP Business Objects BI Platform (Web Intelligence). This vulnerability arises because Web Intelligence does not sufficiently encode user-controlled inputs, potentially allowing attackers to execute malicious scripts.

Impacts of the XSS Vulnerability:

  • Content Defacement: Modify or deface displayed content on a website temporarily.
  • Authentication Theft: Steal user authentication details, including session data.
  • User Impersonation: Gain access to information and functionalities with the same privileges as the affected user.

Solution

SAP has implemented improved encoding mechanisms to prevent the execution of injected scripts. To mitigate this vulnerability, apply the relevant support packages listed below.

Reason and prerequisites

The vulnerability exists in the BI Launchpad, where certain workflows fail to properly intercept injected scripts within requests, allowing malicious scripts to be executed.

CVSS

Score 5.4 Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

References

Full note on SAP: SAP Support Launchpad note 2817937

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More