cbcvebase.
CVE-2018-2397
published 2018-03-14

CVE-2018-2397: In SAP Business Objects Business Intelligence Platform, 4.00, 4.10, 4.20, 4.30, the Central Management Console (CMC) does not sufficiently encode user…

medium5.4CVSS 3.0
AVNACLPRLUIRSCCLILAN
In SAP Business Objects Business Intelligence Platform, 4.00, 4.10, 4.20, 4.30, the Central Management Console (CMC) does not sufficiently encode user controlled inputs which results in Cross-Site Scripting.

Affected

8 ranges
VendorProductVersion rangeFixed in
sapbusinessobjects_business_intelligence_platform
sapbusinessobjects_business_intelligence_platform
sapbusinessobjects_business_intelligence_platform
sapbusinessobjects_business_intelligence_platform
sap_sesap_business_objects_business_intelligence_platform
sap_sesap_business_objects_business_intelligence_platform
sap_sesap_business_objects_business_intelligence_platform
sap_sesap_business_objects_business_intelligence_platform