sap businessobjects-business-intelligence-platform CVE-2022-28216 is a vulnerability in SAP Businessobjects Business Intelligence Platform
Published on April 12, 2022

SAP BusinessObjects Business Intelligence Platform (BI Workspace) - version 420, is susceptible to a Cross-Site Scripting attack by an unauthenticated attacker due to improper sanitization of the user inputs on the network. On successful exploitation, an attacker can access certain reports causing a limited impact on confidentiality of the application data.

NVD

Weakness Type

What is a XSS Vulnerability?

The software does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

CVE-2022-28216 has been classified to as a XSS vulnerability or weakness.


Products Associated with CVE-2022-28216

Want to know whenever a new CVE is published for SAP Businessobjects Business Intelligence Platform? stack.watch will email you.

 

Affected Versions

SAP SE SAP BusinessObjects Business Intelligence Platform (BI Workspace) Version 420 is affected by CVE-2022-28216

Exploit Probability

EPSS
2.31%
Percentile
84.52%

EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.