SAP security note 2693962, "CVE-2019-0269 XSS Vulnerability in SAP BusinessObjects BIWorkspace". Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
A Cross-Site Scripting (XSS) vulnerability has been identified in SAP BusinessObjects BIWorkspace. The application fails to sufficiently encode user-controlled inputs, which can be exploited to execute malicious scripts.
- Content Modification: Attackers can deface or modify displayed content on the affected website.
- Authentication Theft: Sensitive authentication information, including session data, can be stolen.
- User Impersonation: Attackers can impersonate users and access information with the same privileges as the targeted user.
Solution
This vulnerability is addressed in the patches listed under the "Support Packages & Patches" section of the SAP Security Note. It’s crucial to apply the relevant patches to mitigate the risk.
References
- CVE-2019-0269 Details
- BI 4.x Maintenance Strategy & Schedule
Affected components
- SAP BusinessObjects Business Intelligence Platform 4.1
- SAP BusinessObjects Business Intelligence Platform 4.2
Full note on SAP: SAP Support Launchpad note 2693962
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
