Vulnerability Details CVE-2018-2397
In SAP Business Objects Business Intelligence Platform, 4.00, 4.10, 4.20, 4.30, the Central Management Console (CMC) does not sufficiently encode user controlled inputs which results in Cross-Site Scripting.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 38.6%
CVSS Severity
CVSS v3 Score 5.4
CVSS v2 Score 3.5
Products affected by CVE-2018-2397
-
cpe:2.3:a:sap:businessobjects_business_intelligence_platform:4.00
-
cpe:2.3:a:sap:businessobjects_business_intelligence_platform:4.10
-
cpe:2.3:a:sap:businessobjects_business_intelligence_platform:4.20
-
cpe:2.3:a:sap:businessobjects_business_intelligence_platform:4.30