SAP Security Note
SAP security note 2830578, "[CVE-2019-0395] Cross-Site Scripting (XSS) vulnerability in SAP BusinessObjects Business Intelligence Platform (Fiori BI Launchpad)", released on December 10, 2019. Below are the symptom and SAP recommended solution.
Description
Symptom
SAP BusinessObjects Business Intelligence Platform (Fiori BI Launchpad) does not sufficiently encode user-controlled inputs, resulting in a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to deface or modify displayed content on a website temporarily, steal authentication information such as data related to the user’s current session, and impersonate the user to access information with the user’s privileges.
Exploitation of this vulnerability can lead to unauthorized actions being performed on behalf of the user, potential data theft, and compromised user sessions.
Solution
Sanitization has been added for the UI5 HTML control in BIWorkspace to address this vulnerability. Apply the relevant support packages and patches for the affected release.
CVSS
Score 5.4
References
Full note on SAP: SAP Support Launchpad note 2830578
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
