vendor:
SAP BusinessObjects
by:
7.5
CVSS
HIGH
URI-redirection and cross-site scripting
CWE
Product Name: SAP BusinessObjects
Affected Version From:
Affected Version To:
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
SAP BusinessObjects URI-Redirection and Cross-Site Scripting Vulnerabilities
The vulnerability exists due to the insufficient sanitization of user-supplied input in SAP BusinessObjects. Attackers can exploit these issues to execute arbitrary script or HTML code, steal cookie-based authentication credentials, and conduct phishing attacks.
Mitigation:
It is recommended to sanitize user-supplied input to prevent these vulnerabilities. Additionally, users can apply patches or updates provided by SAP to address these issues.