Content Spoofing Vulnerability in SAP Business Objects BI Platform
CVE-2020-6223

6.1MEDIUM

Key Information:

Vendor
SAP
Vendor
CVE Published:
14 April 2020

Summary

The SAP Business Objects Business Intelligence Platform, specifically versions 4.1 and 4.2, is susceptible to a content spoofing vulnerability that allows an attacker to manipulate specific error pages. This manipulation can lead to the inclusion of malicious content within these pages, potentially deceiving users into accessing them unknowingly. The results can mislead users, posing security risks and undermining user trust in the application.

Affected Version(s)

SAP Business Objects Business Intelligence Platform < 4.1 < 4.1

SAP Business Objects Business Intelligence Platform < 4.2 < 4.2

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.