Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-23856


In SAP BusinessObjects Business Intelligence (Web Intelligence user interface) - version 430, some calls return json with wrong content type in the header of the response. As a result, a custom application that calls directly the jsp of Web Intelligence DHTML may be vulnerable to XSS attacks. On successful exploitation an attacker can cause a low impact on integrity of the application.


Published

2023-02-14T04:15:11.860

Last Modified

2024-11-21T07:46:58.843

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 4.3 (MEDIUM)

Weaknesses
  • Type: Primary
    CWE-79

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application sap business_objects_business_intelligence_platform 430 Yes

References