CVE-2019-0251

Severity
6.1MEDIUM
EPSS
0.3%
top 45.43%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 15
Latest updateMay 14

Description

The Fiori Launchpad of SAP BusinessObjects, before versions 4.2 and 4.3, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7

🔴Vulnerability Details

2
GHSA
GHSA-r596-jxm2-frpw: The Fiori Launchpad of SAP BusinessObjects, before versions 42022-05-14
CVEList
CVE-2019-0251: The Fiori Launchpad of SAP BusinessObjects, before versions 42019-02-15