Vulnerability Description
Due to insufficient CSRF protection, SAP BusinessObjects Business Intelligence Platform (Monitoring Application), before versions 4.1, 4.2 and 4.3, may lead to an authenticated user to send unintended request to the web server, leading to Cross Site Request Forgery.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Sap | Businessobjects Business Intelligence Platform | 4.1 |
Related Weaknesses (CWE)
References
- https://launchpad.support.sap.com/#/notes/2701027Permissions Required
- https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=533660397Vendor Advisory
- https://launchpad.support.sap.com/#/notes/2701027Permissions Required
- https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=533660397Vendor Advisory
FAQ
What is CVE-2019-0398?
CVE-2019-0398 is a vulnerability with a CVSS score of 8.8 (HIGH). Due to insufficient CSRF protection, SAP BusinessObjects Business Intelligence Platform (Monitoring Application), before versions 4.1, 4.2 and 4.3, may lead to an authenticated user to send unintended...
How severe is CVE-2019-0398?
CVE-2019-0398 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-0398?
Check the references section above for vendor advisories and patch information. Affected products include: Sap Businessobjects Business Intelligence Platform.