Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2023-0015

Опубликовано: 10 янв. 2023
Источник: nvd
CVSS3: 4.6
CVSS3: 5.4
EPSS Низкий

Описание

In SAP BusinessObjects Business Intelligence Platform (Web Intelligence user interface) - version 420, some calls return json with wrong content type in the header of the response. As a result, a custom application that calls directly the jsp of Web Intelligence DHTML may be vulnerable to XSS attacks. On successful exploitation an attacker can cause limited impact on confidentiality and integrity of the application.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:sap:business_objects_business_intelligence_platform:420:*:*:*:*:*:*:*

EPSS

Процентиль: 62%
0.00434
Низкий

4.6 Medium

CVSS3

5.4 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 5.4
github
около 3 лет назад

In SAP BusinessObjects Business Intelligence Platform (Web Intelligence user interface) - version 420, some calls return json with wrong content type in the header of the response. As a result, a custom application that calls directly the jsp of Web Intelligence DHTML may be vulnerable to XSS attacks. On successful exploitation an attacker can cause limited impact on confidentiality and integrity of the application.

EPSS

Процентиль: 62%
0.00434
Низкий

4.6 Medium

CVSS3

5.4 Medium

CVSS3

Дефекты

CWE-79