Rewterz penetration testing services help organizations determine if a cyber attacker can gain access to their critical assets while giving them detailed insights of the overall business impact of a cyber attack.
Before Rewterz got its start, the market was in dire need of a specialized and dedicated information security company. It was nearly impossible for businesses to find a trustworthy provider that could truly cover all of their bases. We wanted to meet this need, giving companies across the globe a chance to get ahead while knowing that their data is in good hands.
Rewterz penetration testing services help organizations determine if a cyber attacker can gain access to their critical assets while giving them detailed insights of the overall business impact of a cyber attack.
Before Rewterz got its start, the market was in dire need of a specialized and dedicated information security company. It was nearly impossible for businesses to find a trustworthy provider that could truly cover all of their bases. We wanted to meet this need, giving companies across the globe a chance to get ahead while knowing that their data is in good hands.
Severity
Medium
Analysis Summary
Multiple vulnerabilities have been reported in SAP BusinessObjects BI, which can be exploited by malicious users to disclose sensitive information and cause a DoS (Denial of Service) and by malicious people to conduct cross-site scripting attacks.
CVE-2019-0268
SAP BusinessObjects Business Intelligence Platform (CMC Module), versions 4.10, 4.20 and 4.30, does not sufficiently validate an XML document accepted from an untrusted source. It can be exploited to disclose otherwise restricted information or cause a DoS condition via a specially crafted XML document including external entity references.
CVE-2019-0269
In SAP BusinessObjects Business Intelligence Platform (BI Workspace), versions 4.10 and 4.20, certain input related to BI Workspace is not properly sanitised before being returned to the user. This can be exploited to execute arbitrary HTML and script code in a user’s browser session in context of an affected site.
Impact
Affected Products
SAP BusinessObjects BI 4.x
Remediation
Apply SAP Notes 2689259 and 2693962.
https://launchpad.support.sap.com/#/notes/2689259
https://launchpad.support.sap.com/#/notes/2693962