Insufficient CSRF Protection in SAP BusinessObjects Business Intelligence Platform (Monitoring Application) Allows Cross Site Request Forgery

Insufficient CSRF Protection in SAP BusinessObjects Business Intelligence Platform (Monitoring Application) Allows Cross Site Request Forgery

CVE-2019-0398 · HIGH Severity

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Due to insufficient CSRF protection, SAP BusinessObjects Business Intelligence Platform (Monitoring Application), before versions 4.1, 4.2 and 4.3, may lead to an authenticated user to send unintended request to the web server, leading to Cross Site Request Forgery.

Learn more about our Web App Pen Testing.