CVE-2018-2397: SAP Businessobjects Business Intelligence Platform
Medium severity, CVSS 5.4. EPSS: 0.9% chance of exploitation in the next 30 days.
In SAP Business Objects Business Intelligence Platform, 4.00, 4.10, 4.20, 4.30, the Central Management Console (CMC) does not sufficiently encode user controlled inputs which results in Cross-Site Scripting.
Affected products
- SAP Businessobjects Business Intelligence Platform: version 4.00 only; version 4.10 only; version 4.20 only; version 4.30 only
Published 2018-03-14. Last modified 2026-06-17.