Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-v629-5xqh-x8rp

Опубликовано: 11 мар. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 5.4

Описание

SAP BusinessObjects Business Intelligence Platform (Web Intelligence) contains a deprecated web application endpoint that is not properly secured. An attacker could take advantage of this by injecting a malicious url in the data returned to the user. On successful exploitation, there could be a limited impact on confidentiality and integrity within the scope of victim�s browser. There is no impact on availability.

SAP BusinessObjects Business Intelligence Platform (Web Intelligence) contains a deprecated web application endpoint that is not properly secured. An attacker could take advantage of this by injecting a malicious url in the data returned to the user. On successful exploitation, there could be a limited impact on confidentiality and integrity within the scope of victim�s browser. There is no impact on availability.

EPSS

Процентиль: 22%
0.00071
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 5.4
nvd
11 месяцев назад

SAP BusinessObjects Business Intelligence Platform (Web Intelligence) contains a deprecated web application endpoint that is not properly secured. An attacker could take advantage of this by injecting a malicious url in the data returned to the user. On successful exploitation, there could be a limited impact on confidentiality and integrity within the scope of victim�s browser. There is no impact on availability.

CVSS3: 5.4
fstec
11 месяцев назад

Уязвимость компонента Web Intelligence платформы бизнес-аналитики SAP BusinessObjects Business Intelligence Platform, позволяющая нарушителю провести атаку межсайтового скриптинга (XSS)

EPSS

Процентиль: 22%
0.00071
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-79