Content Spoofing Vulnerability in SAP Business Objects BI Platform
CVE-2020-6223
6.1MEDIUM
Key Information:
- Vendor
- SAP
- Vendor
- CVE Published:
- 14 April 2020
Summary
The SAP Business Objects Business Intelligence Platform, specifically versions 4.1 and 4.2, is susceptible to a content spoofing vulnerability that allows an attacker to manipulate specific error pages. This manipulation can lead to the inclusion of malicious content within these pages, potentially deceiving users into accessing them unknowingly. The results can mislead users, posing security risks and undermining user trust in the application.
Affected Version(s)
SAP Business Objects Business Intelligence Platform < 4.1 < 4.1
SAP Business Objects Business Intelligence Platform < 4.2 < 4.2
References
CVSS V3.1
Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved