Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Cross-Site Scripting (XSS) vulnerability in SAP BusinessObjects Web Intelligence HTML interface, SAP security note 2386814

SAP Note 2386814

SAP security note 2386814, "Cross-Site Scripting (XSS) vulnerability in SAP BusinessObjects Web Intelligence HTML interface", is a note. Below are the symptom, SAP recommended solution and the affected software components.

Description

Symptom

SAP BusinessObjects Web Intelligence HTML interface does not sufficiently encode user-controlled inputs, resulting in a Cross-Site Scripting (XSS) vulnerability. This issue allows attackers to:

  • Deface or modify displayed content on a website.
  • Steal authentication information, such as session data.
  • Impersonate users and access information with the same privileges.

Solution

User input text is now properly encoded and interpreted as text values.

CVSS

Score 5.4 Vector: AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

Affected components

  • SAP Business Intelligence Platform Servers versions 4.0, 4.1, and 4.2

Full note on SAP: SAP Support Launchpad note 2386814

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More