Unrestricted file upload in SAP BusinessObjects Business Intelligence suite - CVE-2019-0259
Published: February 18, 2019
Vulnerability identifier: #VU17730
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-0259
CWE-ID: CWE-434
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to bypass security restrictions.
The vulnerability exists due to unrestricted file upload. A remote attacker can supply specially crafted input, trick the victim into processing it and bypass security restrictions to conduct further attacks.
Affected software
SAP BusinessObjects Business Intelligence suite
How to mitigate CVE-2019-0259
Install update from vendor's website.