Vulnerability Description
In SAP Business Objects Business Intelligence Platform, 4.00, 4.10, 4.20, 4.30, the Central Management Console (CMC) does not sufficiently encode user controlled inputs which results in Cross-Site Scripting.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Sap | Businessobjects Business Intelligence Platform | 4.00 |
Related Weaknesses (CWE)
References
- http://www.securityfocus.com/bid/103373Third Party AdvisoryVDB Entry
- https://blogs.sap.com/2018/03/13/sap-security-patch-day-march-2018/Vendor Advisory
- https://launchpad.support.sap.com/#/notes/2550538Permissions Required
- http://www.securityfocus.com/bid/103373Third Party AdvisoryVDB Entry
- https://blogs.sap.com/2018/03/13/sap-security-patch-day-march-2018/Vendor Advisory
- https://launchpad.support.sap.com/#/notes/2550538Permissions Required
FAQ
What is CVE-2018-2397?
CVE-2018-2397 is a vulnerability with a CVSS score of 5.4 (MEDIUM). In SAP Business Objects Business Intelligence Platform, 4.00, 4.10, 4.20, 4.30, the Central Management Console (CMC) does not sufficiently encode user controlled inputs which results in Cross-Site Scr...
How severe is CVE-2018-2397?
CVE-2018-2397 has been rated MEDIUM with a CVSS base score of 5.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-2397?
Check the references section above for vendor advisories and patch information. Affected products include: Sap Businessobjects Business Intelligence Platform.