Vulnerability Details CVE-2019-0334
When creating a module in SAP BusinessObjects Business Intelligence Platform (BI Workspace), versions 4.1, 4.2, 4.3, it is possible to store a malicious script which when executed later could potentially allow a user to escalate privileges via session hijacking. The attacker could also access other sensitive information, leading to Stored Cross Site Scripting.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 44.7%
CVSS Severity
CVSS v3 Score 5.4
CVSS v2 Score 4.9
Products affected by CVE-2019-0334
-
cpe:2.3:a:sap:businessobjects_business_intelligence:4.1
-
cpe:2.3:a:sap:businessobjects_business_intelligence:4.2
-
cpe:2.3:a:sap:businessobjects_business_intelligence:4.3