CVE-2024-28165

Description

SAP Business Objects Business Intelligence Platform is vulnerable to stored XSS allowing an attacker to manipulate a parameter in the Opendocument URL which could lead to high impact on Confidentiality and Integrity of the application

Risk Information

Base Score
9.3
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N
EPSS Score
Exploitation Probability
0.485

Associated Vulnerability

VulnerabilityOS Platform
Multiple Vulnerabilities are affected in SAP Business Objects Business Intelligence Platform 430Windows
Multiple Vulnerabilities are affected in SAP BusinessObjects Business Intelligence Platform (Web Intelligence) 430Windows
Vulnerabilities CVE-2024-28165,CVE-2024-33004,CVE-2024-34684 are affected in SAP Business Objects Business Intelligence Platform 440Windows
Vulnerabilities CVE-2024-28165,CVE-2024-33004,CVE-2024-34684 are affected in SAP BusinessObjects Business Intelligence Platform (Web Intelligence) 440Windows

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234