CVE-2019-0396
Summary
| CVE | CVE-2019-0396 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-11-13 23:15:00 UTC |
| Updated | 2019-11-15 20:49:00 UTC |
| Description | SAP BusinessObjects Business Intelligence Platform (Web Intelligence HTML interface), corrected in versions 4.1 and 4.2, does not sufficiently validate an XML document accepted from an untrusted source. An attacker can craft a message that contains malicious elements that will not be correctly filtered by Web Intelligence HTML interface in some specific workflows. |
Risk And Classification
Problem Types: CWE-20
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Sap | Businessobjects Business Intelligence Platform | 4.0 | All | All | All |
| Application | Sap | Businessobjects Business Intelligence Platform | 4.1 | sp10 | All | All |
| Application | Sap | Businessobjects Business Intelligence Platform | 4.1 | sp11 | All | All |
| Application | Sap | Businessobjects Business Intelligence Platform | 4.1 | sp12 | All | All |
| Application | Sap | Businessobjects Business Intelligence Platform | 4.0 | All | All | All |
| Application | Sap | Businessobjects Business Intelligence Platform | 4.1 | sp10 | All | All |
| Application | Sap | Businessobjects Business Intelligence Platform | 4.1 | sp11 | All | All |
| Application | Sap | Businessobjects Business Intelligence Platform | 4.1 | sp12 | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| SAP Security Patch Day – November 2019 - Product Security Response at SAP - Community Wiki | MISC | wiki.scn.sap.com | Vendor Advisory |
| launchpad.support.sap.com | MISC | launchpad.support.sap.com | Permissions Required, Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.