Code Injection Vulnerability in SAP Business Objects Business Intelligence Platform
CVE-2020-6208
Key Information:
- Vendor
SAP
- Vendor
- CVE Published:
- 10 March 2020
What is CVE-2020-6208?
The SAP Business Objects Business Intelligence Platform, particularly in its Crystal Reports component, is susceptible to a code injection vulnerability. An attacker with basic authorization can leverage this flaw to inject malicious code that the application executes. While the attack vector is classified as local, the implications can affect multiple applications within the environment, potentially allowing an attacker to manipulate the application's behavior and execute arbitrary code.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
SAP Business Objects Business Intelligence Platform (Crystal Reports) < 4.1 < 4.1
SAP Business Objects Business Intelligence Platform (Crystal Reports) < 4.2 < 4.2
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved