CVE-2019-0396
Status: ModifiedHigh (7.1)—
SAP BusinessObjects Business Intelligence Platform (Web Intelligence HTML interface), corrected in versions 4.1 and 4.2, does not sufficiently validate an XML document accepted from an untrusted source. An attacker can craft a message that contains malicious elements that will not be correctly filtered by Web Intelligence HTML interface in some specific workflows.
CVSS
- Version: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H
- Base score: 7.1
Exploitation probability (EPSS)
- Probability of exploitation in the next 30 days: 0.90%
- Percentile among all scored CVEs: 58
- Score date: 10/6/2026
EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).
Affected technologies (1)
CWEs
- CWE-20
References
Raw JSON (NVD)
Show
{
"id": "CVE-2019-0396",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 5.5,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:S/C:P/I:N/A:P",
"authentication": "SINGLE",
"integrityImpact": "NONE",
"accessComplexity": "LOW",
"availabilityImpact": "PARTIAL",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 4.9,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 8,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
],
"cvssMetricV31": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 7.1,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "LOW",
"confidentialityImpact": "LOW"
},
"impactScore": 4.2,
"exploitabilityScore": 2.8
}
]
},
"affected": [
{
"source": "cna@sap.com",
"affectedData": [
{
"vendor": "SAP SE",
"product": "SAP BusinessObjects Business Intelligence Platform (Web Intelligence HTML interface)",
"versions": [
{
"status": "affected",
"version": "< 4.1"
},
{
"status": "affected",
"version": "< 4.2"
}
]
}
]
}
],
"published": "2019-11-13T23:15:11.137",
"references": [
{
"url": "https://launchpad.support.sap.com/#/notes/2814007",
"tags": [
"Permissions Required",
"Vendor Advisory"
],
"source": "cna@sap.com"
},
{
"url": "https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=528880390",
"tags": [
"Vendor Advisory"
],
"source": "cna@sap.com"
},
{
"url": "https://launchpad.support.sap.com/#/notes/2814007",
"tags": [
"Permissions Required",
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=528880390",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-20"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "SAP BusinessObjects Business Intelligence Platform (Web Intelligence HTML interface), corrected in versions 4.1 and 4.2, does not sufficiently validate an XML document accepted from an untrusted source. An attacker can craft a message that contains malicious elements that will not be correctly filtered by Web Intelligence HTML interface in some specific workflows."
},
{
"lang": "es",
"value": "SAP BusinessObjects Business Intelligence Platform (interfaz HTML de Web Intelligence), corregida en las versiones 4.1 y 4.2, no comprueba suficientemente un documento XML aceptado desde una fuente no segura. Un atacante puede crear un mensaje que contenga elementos maliciosos que no serán filtrados correctamente por parte de la interfaz HTML de Web Intelligence en algunos flujos de trabajo específicos."
}
],
"lastModified": "2026-06-17T02:08:18.253",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:sap:businessobjects_business_intelligence_platform:4.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "53357CC3-3B5F-46C7-85F9-6720F90356AA"
},
{
"criteria": "cpe:2.3:a:sap:businessobjects_business_intelligence_platform:4.1:sp10:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "9B7D6DFB-22A7-431E-AD9F-6B5D60AF8228"
},
{
"criteria": "cpe:2.3:a:sap:businessobjects_business_intelligence_platform:4.1:sp11:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "B0A9D8CA-6FE7-447A-8B81-3A48E50E5596"
},
{
"criteria": "cpe:2.3:a:sap:businessobjects_business_intelligence_platform:4.1:sp12:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "D1022670-FBD9-451B-97B4-2DE8BB38FC03"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cna@sap.com"
}