SAP BusinessObjects Business Intelligence Platform (Web Intelligence HTML interface), before version 4.2, does not sufficiently encode user-controlled inputs and allows an attacker to store malicious scripts in the file name of the background image resulting in Stored Cross-Site Scripting.
| Software | From | Fixed in |
|---|---|---|
| sap / businessobjects_business_intelligence_platform | 4.0 | 4.0.x |
| sap / businessobjects_business_intelligence_platform | 4.1 | 4.1.x |
| sap / businessobjects_business_intelligence_platform | 4.1-sp12 | 4.1-sp12.x |
| sap / businessobjects_business_intelligence_platform | 4.1-sp11 | 4.1-sp11.x |
| sap / businessobjects_business_intelligence_platform | 4.1-sp10 | 4.1-sp10.x |