CVE-2018-2431Cross-site Scripting in SAP Businessobjects Business Intelligence Suite

Severity
6.1MEDIUMNVD
EPSS
0.4%
top 38.16%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 10
Latest updateMay 14

Description

SAP BusinessObjects Business Intelligence Suite, versions 4.10 and 4.20, does not sufficiently encode user controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7

Affected Packages2 packages

Patches

🔴Vulnerability Details

2
GHSA
GHSA-4r6w-8469-h8vg: SAP BusinessObjects Business Intelligence Suite, versions 42022-05-14
CVEList
CVE-2018-2431: SAP BusinessObjects Business Intelligence Suite, versions 42018-07-10
CVE-2018-2431 — Cross-site Scripting in SAP | cvebase