SAP BusinessObjects Multiple Input Validation Vulnerabilities
BID:37900
Info
SAP BusinessObjects Multiple Input Validation Vulnerabilities
| Bugtraq ID: | 37900 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 18 2010 12:00AM |
| Updated: | Jan 21 2010 05:32PM |
| Credit: | Richard Brain - ProCheckUp |
| Vulnerable: |
SAP Business Objects XI 3.10 |
| Not Vulnerable: | |
Discussion
SAP BusinessObjects Multiple Input Validation Vulnerabilities
SAP BusinessObjects is prone to multiple input-validation vulnerabilities, including cross-site scripting issues, remote URI-redirection issues, and information-disclosure issues, because the application fails to sufficiently sanitize user-supplied input.
An attacker can exploit these issues to steal cookie-based authentication credentials, perform phishing attacks, and obtain sensitive information. Other attacks are also possible.
These issues affect BusinessObjects XI 3.x (12.x).
SAP BusinessObjects is prone to multiple input-validation vulnerabilities, including cross-site scripting issues, remote URI-redirection issues, and information-disclosure issues, because the application fails to sufficiently sanitize user-supplied input.
An attacker can exploit these issues to steal cookie-based authentication credentials, perform phishing attacks, and obtain sensitive information. Other attacks are also possible.
These issues affect BusinessObjects XI 3.x (12.x).
Solution / Fix
SAP BusinessObjects Multiple Input Validation Vulnerabilities
Solution:
Reports indicate that some of these issues were fixed. Please see the references and contact the vendor for more information.
Solution:
Reports indicate that some of these issues were fixed. Please see the references and contact the vendor for more information.