Unrated severityNVD Advisory· Published Jul 10, 2018· Updated Aug 5, 2024
CVE-2018-2432
CVE-2018-2432
Description
SAP BusinessObjects Business Intelligence (BI Launchpad and Central Management Console) versions 4.10, 4.20 and 4.30 allow an attacker to include invalidated data in the HTTP response header sent to a Web user. Successful exploitation of this vulnerability may lead to advanced attacks, including: cross-site scripting and page hijacking.
Affected products
2- Range: 4.10, 4.20, 4.30
- Range: = 4.10
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- www.securityfocus.com/bid/104716mitrevdb-entryx_refsource_BID
- launchpad.support.sap.commitrex_refsource_MISC
- wiki.scn.sap.com/wiki/pages/viewpage.actionmitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.