Unrestricted file upload in SAP BusinessObjects Business Intelligence suite - CVE-2019-0259

 

Unrestricted file upload in SAP BusinessObjects Business Intelligence suite - CVE-2019-0259

Published: February 18, 2019


Vulnerability identifier: #VU17730
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-0259
CWE-ID: CWE-434
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass security restrictions.

The vulnerability exists due to unrestricted file upload. A remote attacker can supply specially crafted input, trick the victim into processing it and bypass security restrictions to conduct further attacks.


Affected software

SAP BusinessObjects Business Intelligence suite

How to mitigate CVE-2019-0259

Install update from vendor's website.


External References

Related Security Bulletins