SAP BusinessObjects Business Intelligence Platform
cpe:2.3:a:sap:businessobjects_bi_platform:*:*:*:*:*:*:*, +3 more
A cross-site scripting vulnerability has been identified in SAP BusinessObjects Business Intelligence Platform, specifically within Web Intelligence reports. This issue allows an attacker to inject JavaScript code that is executed in the browser of the victim each time the affected page is accessed. The vulnerability arises only when script or HTML execution is enabled by the administrator in the Central Management Console.
Exploitation of this vulnerability could lead to cross-site scripting, allowing for the injection and execution of malicious scripts in the context of the user's browser.
Users are advised to review and implement the SAP Security Note related to this vulnerability, available through the SAP for Me platform. This vulnerability can be addressed by disabling script or HTML execution in the Central Management Console.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.