← back
CVE-2018-2432

CVE-2018-2432

EPSS 0.7%
SAP BusinessObjects Business Intelligence (BI Launchpad and Central Management Console) versions 4.10, 4.20 and 4.30 allow an attacker to include invalidated data in the HTTP response header sent to a Web user. Successful exploitation of this vulnerability may lead to advanced attacks, including: cross-site scripting and page hijacking.

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →