PT-2023-28363 · Sap · Sap Businessobjects Business Intelligence Platform

CVE-2023-42478

·

Publicado

2023-12-11

·

Atualizado

2023-12-13

CVSS v3.1

7.6

Alta

VetorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:H/A:N
Name of the Vulnerable Software and Affected Versions SAP Business Objects Business Intelligence Platform (affected versions not specified)
Description The issue allows an attacker to upload agnostic documents in the system, which when opened by any other user, could lead to a high impact on the integrity of the application due to stored XSS.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-42478

Produtos afetados

Sap Businessobjects Business Intelligence Platform