Cross Site Scripting vulnerability in SAP BusinessObjects Web Intelligence
Vulnerability Description
SAP Business Objects Web Intelligence - version 420, allows an authenticated attacker to inject JavaScript code into Web Intelligence documents which is then executed in the victim’s browser each time the vulnerable page is visited. Successful exploitation can lead to exposure of the data that the user has access to. In the worst case, attacker could access data from reporting databases.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2023-42476
Credits & Attribution
No credits recorded in the NVD database.
References
More from SAP_SE
View All →Affected Vendor
SAP_SE
View all reports →