Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-27939 | In SAP BusinessObjects Business Intelligence (Web Intelligence user interface) - version 430, some calls return json with wrong content type in the header of the response. As a result, a custom application that calls directly the jsp of Web Intelligence DHTML may be vulnerable to XSS attacks. On successful exploitation an attacker can cause a low impact on integrity of the application. |
Thu, 20 Mar 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: sap
Published:
Updated: 2025-03-20T17:55:57.774Z
Reserved: 2023-01-19T00:05:29.415Z
Link: CVE-2023-23856
Updated: 2024-08-02T10:42:26.673Z
Status : Modified
Published: 2023-02-14T04:15:11.860
Modified: 2024-11-21T07:46:58.843
Link: CVE-2023-23856
No data.
OpenCVE Enrichment
No data.
EUVD