CVE-2017-16681: SAP Business Intelligence Promotion Management Application
Medium severity, CVSS 6.1. EPSS: 1% chance of exploitation in the next 30 days.
Cross-Site Scripting (XSS) vulnerability in SAP Business Intelligence Promotion Management Application, Enterprise 4.10, 4.20, 4.30, as user controlled inputs are not sufficiently encoded.
Affected products
- SAP Business Intelligence Promotion Management Application: version 4.10 only; version 4.20 only; version 4.30 only
Published 2017-12-12. Last modified 2026-06-17.