Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

CVE-2019-0374 Multiple Cross-Site Scripting (XSS) vulnerabilities in SAP BusinessObjects Business Intelligence Platform (Web Intelligence HTML interface), SAP security note 2817945

SAP Note 2817945

SAP security note 2817945, "[CVE-2019-0374] Multiple Cross-Site Scripting (XSS) vulnerabilities in SAP BusinessObjects Business Intelligence Platform (Web Intelligence HTML interface)". Below are the symptom, SAP recommended solution and the affected software components.

Description

Symptom

SAP BusinessObjects Business Intelligence Platform (Web Intelligence HTML interface) has multiple Cross-Site Scripting (XSS) vulnerabilities. These vulnerabilities result from insufficient encoding of user-controlled inputs, leading to both reflected and stored XSS attacks. Attackers can exploit these to:

  • Deface or modify displayed content
  • Steal user authentication information or session data
  • Impersonate the user and access information with the same privileges

Solution

User inputs are now properly encoded in the affected workflows. Apply the relevant patches as listed below.

CVSS

Score 5.4 Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

References

Affected components

  • WebI designer
  • Document controls
  • Various other generic locations within the platform

Full note on SAP: SAP Support Launchpad note 2817945

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More