2 results (0.002 seconds)

CVSS: 6.1EPSS: 0%CPEs: 3EXPL: 0

09 Feb 2021 — SAP Business Objects BI Platform, versions - 410, 420, 430, allows multiple X-Frame-Options headers entries in the response headers, which may not be predictably treated by all user agents. This could, as a result, nullify the added X-Frame-Options header leading to Clickjacking attack. SAP Business Objects BI Platform, versiones - 410, 420, 430, permite múltiples entradas de encabezados X-Frame-Options en los encabezados de respuesta, que pueden no ser tratados de manera predecible por todos los agentes de... • https://launchpad.support.sap.com/#/notes/2935791 • CWE-1021: Improper Restriction of Rendered UI Layers or Frames •

CVSS: 5.4EPSS: 0%CPEs: 2EXPL: 0

12 Jan 2021 — SAP BusinessObjects Business Intelligence platform, versions 410, 420, allows an authenticated attacker to inject malicious JavaScript payload into the custom value input field of an Input Control, which can be executed by User who views the relevant application content, which leads to Stored Cross-Site Scripting. La plataforma SAP BusinessObjects Business Intelligence, versiones 410, 420, permite a un atacante autenticado inyectar una carga útil de JavaScript maliciosa en el campo de entrada de valor perso... • https://launchpad.support.sap.com/#/notes/2965154 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •