CVE-2019-1010147: Bmc Remedy Smart Reporting
Medium severity, CVSS 5.4. EPSS: 0.7% chance of exploitation in the next 30 days.
Yellowfin Smart Reporting All Versions Prior to 7.3 is affected by: Incorrect Access Control - Privileges Escalation. The impact is: Victim attacked and access admin functionality through their browser and control browser. The component is: MIAdminStyles.i4. The attack vector is: Victims are typically lured to a web site under the attacker's control; the XSS vulnerability on the target domain is silently exploited without the victim's knowledge. The fixed version is: 7.4 and later.
Affected products
- Bmc Remedy Smart Reporting: affected versions not specified
- Yellowfinbi Yellowfin BI: before 7.3 (fixed in 7.3)
Published 2019-07-26. Last modified 2026-06-17.