CVE-2023-0018
published 2023-01-10CVE-2023-0018: Due to improper input sanitization of user-controlled input in SAP BusinessObjects Business Intelligence Platform CMC application - versions 420, and 430, an…
medium6.1CVSS 3.1
AVNACLPRNUIRSCCLILAN
Due to improper input sanitization of user-controlled input in SAP BusinessObjects Business Intelligence Platform CMC application - versions 420, and 430, an attacker with basic user-level privileges can modify/upload crystal reports containing a malicious payload. Once these reports are viewable, anyone who opens those reports would be susceptible to stored XSS attacks. As a result of the attack, information maintained in the victim's web browser can be read, modified, and sent to the attacker.
Affected
25 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| linux | linux_kernel | >= 2.6.12 < 4.14.308 | 4.14.308 |
| linux | linux_kernel | >= 3.15.0 < 4.14.324 | 4.14.324 |
| linux | linux_kernel | >= 4.15.0 < 4.19.293 | 4.19.293 |
| linux | linux_kernel | >= 4.15.0 < 4.19.276 | 4.19.276 |
| linux | linux_kernel | >= 4.2.0 < 5.4.243 | 5.4.243 |
| linux | linux_kernel | >= 4.20.0 < 5.4.255 | 5.4.255 |
| linux | linux_kernel | >= 4.20.0 < 5.4.235 | 5.4.235 |
| linux | linux_kernel | >= 5.11.0 < 5.15.123 | 5.15.123 |
| linux | linux_kernel | >= 5.11.0 < 5.15.99 | 5.15.99 |
| linux | linux_kernel | >= 5.11.0 < 5.15.112 | 5.15.112 |
| linux | linux_kernel | >= 5.15.121 < 5.15.128 | 5.15.128 |
| linux | linux_kernel | >= 5.16.0 < 6.1.42 | 6.1.42 |
| linux | linux_kernel | >= 5.16.0 < 6.1.16 | 6.1.16 |
| linux | linux_kernel | >= 5.16.0 < 6.1.29 | 6.1.29 |
| linux | linux_kernel | >= 5.5.0 < 5.10.192 | 5.10.192 |
| linux | linux_kernel | >= 5.5.0 < 5.10.173 | 5.10.173 |
| linux | linux_kernel | >= 5.5.0 < 5.10.180 | 5.10.180 |
| linux | linux_kernel | >= 6.1.39 < 6.1.47 | 6.1.47 |
| linux | linux_kernel | >= 6.2.0 < 6.4.7 | 6.4.7 |
| linux | linux_kernel | >= 6.2.0 < 6.2.3 | 6.2.3 |
| linux | linux_kernel | >= 6.2.0 < 6.2.16 | 6.2.16 |
| linux | linux_kernel | >= 6.3.0 < 6.3.3 | 6.3.3 |
| linux | linux_kernel | >= 6.4.4 < 6.4.12 | 6.4.12 |
| sap | businessobjects_business_intelligence_platform | — | — |
| sap | businessobjects_business_intelligence_platform | — | — |
CVSS provenance
nvdv3.16.1MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
cisa7.2HIGH