CVE-2018-2432
SAP BusinessObjects Business Intelligence (BI Launchpad and Central Management Console) versions 4.10, 4.20 and 4.30 allow an attacker to include invalidated data in the HTTP response header sent to a Web user.
Does this matter?
Lower severity and a low EPSS score (0.95%). Track it; it rarely justifies an emergency change on its own.
Description
SAP BusinessObjects Business Intelligence (BI Launchpad and Central Management Console) versions 4.10, 4.20 and 4.30 allow an attacker to include invalidated data in the HTTP response header sent to a Web user. Successful exploitation of this vulnerability may lead to advanced attacks, including: cross-site scripting and page hijacking.
- CVSS 3.1
- 5.4 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
- EPSS
- 0.95% probability · 59th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- sap/businessobjects business intelligence
- Source
- cna@sap.com
References
- http://www.securityfocus.com/bid/104716Third Party Advisory, VDB Entry
- https://launchpad.support.sap.com/#/notes/2523290Permissions Required
- https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=497256000Patch, Vendor Advisory
- http://www.securityfocus.com/bid/104716Third Party Advisory, VDB Entry
- https://launchpad.support.sap.com/#/notes/2523290Permissions Required
- https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=497256000Patch, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.