Loading HuntDB...

GHSA-qwq7-63pm-p4wv

GitHub Security Advisory

⚠ Unreviewed MODERATE Has CVE

Advisory Details

In SAP BusinessObjects Business Intelligence (Web Intelligence user interface) - version 430, some calls return json with wrong content type in the header of the response. As a result, a custom application that calls directly the jsp of Web Intelligence DHTML may be vulnerable to XSS attacks. On successful exploitation an attacker can cause a low impact on integrity of the application.

Related CVEs

Key Information

GHSA ID
GHSA-qwq7-63pm-p4wv
Published
February 14, 2023 6:31 AM
Last Modified
February 22, 2023 6:30 PM
CVSS Score
5.0 /10
Primary Ecosystem
Unknown
Primary Package
Unknown
GitHub Reviewed
✗ No

Dataset

Last updated: September 8, 2025 6:31 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.