Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-12120 | In SAP BusinessObjects Business Intelligence Platform (Web Intelligence user interface) - version 420, some calls return json with wrong content type in the header of the response. As a result, a custom application that calls directly the jsp of Web Intelligence DHTML may be vulnerable to XSS attacks. On successful exploitation an attacker can cause limited impact on confidentiality and integrity of the application. |
Wed, 09 Apr 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: sap
Published:
Updated: 2025-04-09T13:57:34.512Z
Reserved: 2022-12-16T03:13:44.778Z
Link: CVE-2023-0015
Updated: 2024-08-02T04:54:32.587Z
Status : Modified
Published: 2023-01-10T04:15:09.680
Modified: 2024-11-21T07:36:23.863
Link: CVE-2023-0015
No data.
OpenCVE Enrichment
No data.
EUVD