Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-xr92-rw38-fmg9

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

SAP BusinessObjects Business Intelligence Platform (Web Intelligence HTML interface), corrected in versions 4.1 and 4.2, does not sufficiently validate an XML document accepted from an untrusted source. An attacker can craft a message that contains malicious elements that will not be correctly filtered by Web Intelligence HTML interface in some specific workflows.

SAP BusinessObjects Business Intelligence Platform (Web Intelligence HTML interface), corrected in versions 4.1 and 4.2, does not sufficiently validate an XML document accepted from an untrusted source. An attacker can craft a message that contains malicious elements that will not be correctly filtered by Web Intelligence HTML interface in some specific workflows.

EPSS

Процентиль: 62%
0.00425
Низкий

Связанные уязвимости

CVSS3: 7.1
nvd
около 6 лет назад

SAP BusinessObjects Business Intelligence Platform (Web Intelligence HTML interface), corrected in versions 4.1 and 4.2, does not sufficiently validate an XML document accepted from an untrusted source. An attacker can craft a message that contains malicious elements that will not be correctly filtered by Web Intelligence HTML interface in some specific workflows.

CVSS3: 7.1
fstec
около 6 лет назад

Уязвимость платформы бизнес-аналитики SAP BusinessObjects Business Intelligence, существующая из-за недостаточной проверки входных данных, позволяющая нарушителю оказать воздействие на конфиденциальность и доступность защищаемой информации

EPSS

Процентиль: 62%
0.00425
Низкий