CVE-2019-0396
moderate-risk
Published 2019-11-13
SAP BusinessObjects Business Intelligence Platform (Web Intelligence HTML interface), corrected in versions 4.1 and 4.2, does not sufficiently validate an XML document accepted from an untrusted source. An attacker can craft a message that contains malicious elements that will not be correctly filtered by Web Intelligence HTML interface in some specific workflows.
Do I need to act?
-
0.43% chance of exploitation
EPSS score — low exploit probability
-
Not on CISA KEV list
No confirmed active exploitation reported to CISA
?
Patch status unknown
Check vendor advisories for fix availability and mitigation guidance
7
CVSS 7.1/10
High
NETWORK
/ LOW complexity
Affected Products (4)
Affected Vendors
References (4)
Permissions Required
https://launchpad.support.sap.com/#/notes/2814007
Permissions Required
https://launchpad.support.sap.com/#/notes/2814007
37
/ 100
moderate-risk
Severity
25/34 · High
Exploitability
2/34 · Minimal
Exposure
10/34 · Low