CVE Feed

    Dashboard / CVE / CVE-2019-1010147

    CVE-2019-1010147

    Yellowfin Smart Reporting All Versions Prior to 7.3 is affected by: Incorrect Access Control - Privileges Escalation. The impact is: Victim attacked and access admin functionality through their browser and control browser. The component is: MIAdminStyles.i4. The attack vector is: Victims are typically lured to a web site under the attacker's control; the XSS vulnerability on the target domain is silently exploited without the victim's knowledge. The fixed version is: 7.4 and later.

    Published:Jul 25, 2019
    Last Modified:Nov 21, 2024
    EPS:Jul 25, 2019
    EPSS Score:0.00185
    CVSS Score:5.4

    Affected Products

    Vendor
    Bmc
    Product
    Remedy Smart Reporting
    Vendor
    Yellowfinbi
    Product
    Yellowfin Bi

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High