ID

VAR-201203-0407


TITLE

Multiple Cross-Site Scripting Vulnerabilities in SAP Business Objects Infoview

Trust: 0.6

sources: CNVD: CNVD-2012-1153

DESCRIPTION

SAP Business Objects is the product suite of the world's leading business intelligence (BI) software companies, and Business Objects XI provides a platform for reporting, query and analysis, performance management, and data integration. A cross-site scripting vulnerability exists in SAP Business Objects. Because SAP Business Objects fails to properly filter user-submitted input, an attacker can build a malicious URI, entice a user to resolve, gain sensitive information, or hijack a user's session. An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and launch other attacks

Trust: 0.99

sources: CNVD: CNVD-2012-1153 // BID: 52361 // IVD: d2d72216-1f70-11e6-abef-000c29c66e3d

IOT TAXONOMY

category:['ICS']sub_category: -

Trust: 0.8

sources: IVD: d2d72216-1f70-11e6-abef-000c29c66e3d // CNVD: CNVD-2012-1153

AFFECTED PRODUCTS

vendor:sapmodel:business objects xi r2scope: - version: -

Trust: 0.9

vendor:sapmodel:business objects xi r2scope:eqversion:*

Trust: 0.2

sources: IVD: d2d72216-1f70-11e6-abef-000c29c66e3d // CNVD: CNVD-2012-1153 // BID: 52361

CVSS

SEVERITY

CVSSV2

CVSSV3

IVD: d2d72216-1f70-11e6-abef-000c29c66e3d
value: MEDIUM

Trust: 0.2

IVD: d2d72216-1f70-11e6-abef-000c29c66e3d
severity: NONE
baseScore: NONE
vectorString: NONE
accessVector: NONE
accessComplexity: NONE
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: NONE
impactScore: NONE
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: UNKNOWN

Trust: 0.2

sources: IVD: d2d72216-1f70-11e6-abef-000c29c66e3d

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201203-195

TYPE

XSS

Trust: 0.6

sources: CNNVD: CNNVD-201203-195

EXTERNAL IDS

db:BIDid:52361

Trust: 1.5

db:CNVDid:CNVD-2012-1153

Trust: 0.8

db:CNNVDid:CNNVD-201203-195

Trust: 0.6

db:IVDid:D2D72216-1F70-11E6-ABEF-000C29C66E3D

Trust: 0.2

sources: IVD: d2d72216-1f70-11e6-abef-000c29c66e3d // CNVD: CNVD-2012-1153 // BID: 52361 // CNNVD: CNNVD-201203-195

REFERENCES

url:http://seclists.org/bugtraq/2012/mar/34

Trust: 0.6

url:http://www.securityfocus.com/bid/52361

Trust: 0.6

url:msg://bugtraq/201203081001.q28a1kje002835@sf01web1.securityfocus.com

Trust: 0.3

url:http://www.sap.com/solutions/sapbusinessobjects/index.epx

Trust: 0.3

sources: CNVD: CNVD-2012-1153 // BID: 52361 // CNNVD: CNNVD-201203-195

CREDITS

vulns@dionach.com

Trust: 0.9

sources: BID: 52361 // CNNVD: CNNVD-201203-195

SOURCES

db:IVDid:d2d72216-1f70-11e6-abef-000c29c66e3d
db:CNVDid:CNVD-2012-1153
db:BIDid:52361
db:CNNVDid:CNNVD-201203-195

LAST UPDATE DATE

2022-05-17T02:07:18.704000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2012-1153date:2012-03-12T00:00:00
db:BIDid:52361date:2012-03-08T00:00:00
db:CNNVDid:CNNVD-201203-195date:2012-03-12T00:00:00

SOURCES RELEASE DATE

db:IVDid:d2d72216-1f70-11e6-abef-000c29c66e3ddate:2012-03-12T00:00:00
db:CNVDid:CNVD-2012-1153date:2012-03-12T00:00:00
db:BIDid:52361date:2012-03-08T00:00:00
db:CNNVDid:CNNVD-201203-195date:2012-03-12T00:00:00