Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

CVE-2019-0395 Cross-Site Scripting (XSS) vulnerability in SAP BusinessObjects Business Intelligence Platform (Fiori BI Launchpad), SAP security note 2830578

SAP Note 2830578
SAP Security Note

SAP security note 2830578, "[CVE-2019-0395] Cross-Site Scripting (XSS) vulnerability in SAP BusinessObjects Business Intelligence Platform (Fiori BI Launchpad)", released on December 10, 2019. Below are the symptom and SAP recommended solution.

ComponentBI-BIP-INV
TypeSAP Security Note
Released onDecember 10, 2019

Description

Symptom

SAP BusinessObjects Business Intelligence Platform (Fiori BI Launchpad) does not sufficiently encode user-controlled inputs, resulting in a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to deface or modify displayed content on a website temporarily, steal authentication information such as data related to the user’s current session, and impersonate the user to access information with the user’s privileges.

Exploitation of this vulnerability can lead to unauthorized actions being performed on behalf of the user, potential data theft, and compromised user sessions.

Solution

Sanitization has been added for the UI5 HTML control in BIWorkspace to address this vulnerability. Apply the relevant support packages and patches for the affected release.

CVSS

Score 5.4

References

Full note on SAP: SAP Support Launchpad note 2830578

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More