« Volver al listado

CVE-2019-0396

Estado: ModificadaAlta (7.1)—

SAP BusinessObjects Business Intelligence Platform (Web Intelligence HTML interface), corrected in versions 4.1 and 4.2, does not sufficiently validate an XML document accepted from an untrusted source. An attacker can craft a message that contains malicious elements that will not be correctly filtered by Web Intelligence HTML interface in some specific workflows.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2019-0396",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 5.5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:S/C:P/I:N/A:P",
          "authentication": "SINGLE",
          "integrityImpact": "NONE",
          "accessComplexity": "LOW",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 4.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.1,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 4.2,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "cna@sap.com",
      "affectedData": [
        {
          "vendor": "SAP SE",
          "product": "SAP BusinessObjects Business Intelligence Platform (Web Intelligence HTML interface)",
          "versions": [
            {
              "status": "affected",
              "version": "< 4.1"
            },
            {
              "status": "affected",
              "version": "< 4.2"
            }
          ]
        }
      ]
    }
  ],
  "published": "2019-11-13T23:15:11.137",
  "references": [
    {
      "url": "https://launchpad.support.sap.com/#/notes/2814007",
      "tags": [
        "Permissions Required",
        "Vendor Advisory"
      ],
      "source": "cna@sap.com"
    },
    {
      "url": "https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=528880390",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cna@sap.com"
    },
    {
      "url": "https://launchpad.support.sap.com/#/notes/2814007",
      "tags": [
        "Permissions Required",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=528880390",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-20"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "SAP BusinessObjects Business Intelligence Platform (Web Intelligence HTML interface), corrected in versions 4.1 and 4.2, does not sufficiently validate an XML document accepted from an untrusted source. An attacker can craft a message that contains malicious elements that will not be correctly filtered by Web Intelligence HTML interface in some specific workflows."
    },
    {
      "lang": "es",
      "value": "SAP BusinessObjects Business Intelligence Platform (interfaz HTML de Web Intelligence), corregida en las versiones 4.1 y 4.2, no comprueba suficientemente un documento XML aceptado desde una fuente no segura. Un atacante puede crear un mensaje que contenga elementos maliciosos que no serán filtrados correctamente por parte de la interfaz HTML de Web Intelligence en algunos flujos de trabajo específicos."
    }
  ],
  "lastModified": "2026-06-17T02:08:18.253",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:sap:businessobjects_business_intelligence_platform:4.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "53357CC3-3B5F-46C7-85F9-6720F90356AA"
            },
            {
              "criteria": "cpe:2.3:a:sap:businessobjects_business_intelligence_platform:4.1:sp10:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9B7D6DFB-22A7-431E-AD9F-6B5D60AF8228"
            },
            {
              "criteria": "cpe:2.3:a:sap:businessobjects_business_intelligence_platform:4.1:sp11:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B0A9D8CA-6FE7-447A-8B81-3A48E50E5596"
            },
            {
              "criteria": "cpe:2.3:a:sap:businessobjects_business_intelligence_platform:4.1:sp12:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D1022670-FBD9-451B-97B4-2DE8BB38FC03"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cna@sap.com"
}