Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

CVE-2018-2479 Cross-site Scripting vulnerability in BIWorkspace, SAP security note 2676094

SAP Note 2676094

SAP security note 2676094, "[CVE-2018-2479] Cross-site Scripting vulnerability in BIWorkspace". Below are the symptom and the SAP recommended solution.

Description

Symptom

BIWorkspace does not sufficiently encode user-controlled inputs, resulting in a Cross-Site Scripting (XSS) vulnerability.

Solution

This issue is fixed in the patches listed in the Support Packages & Patches section. For Business Intelligence Platform maintenance schedule and strategy, see the Knowledge Base Article 2144559.

CVSS

Score 6.1/10 Vector: AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

References

Full note on SAP: SAP Support Launchpad note 2676094

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More