CVE-2019-0382Cross-site Scripting in SE SAP Businessobjects Business Intelligence Platform

Severity
5.4MEDIUMNVD
EPSS
0.3%
top 47.30%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 13
Latest updateMay 24

Description

A Cross-Site Scripting vulnerability exists in SAP BusinessObjects Business Intelligence Platform (Web Intelligence-Publication related pages); corrected in version 4.2. Privileges are required in order to exploit this vulnerability.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:NExploitability: 2.3 | Impact: 2.7

🔴Vulnerability Details

2
GHSA
GHSA-732q-646p-qgpp: A Cross-Site Scripting vulnerability exists in SAP BusinessObjects Business Intelligence Platform (Web Intelligence-Publication related pages); correc2022-05-24
CVEList
CVE-2019-0382: A Cross-Site Scripting vulnerability exists in SAP BusinessObjects Business Intelligence Platform (Web Intelligence-Publication related pages); correc2019-11-13
CVE-2019-0382 — Cross-site Scripting | cvebase