Improper Resource Identifier Control in SAP Business Objects Platform
CVE-2020-6245

6.5MEDIUM

Key Information:

Vendor
SAP
Vendor
CVE Published:
12 May 2020

Summary

The SAP Business Objects Business Intelligence Platform version 4.2 is susceptible to a vulnerability that allows an authenticated attacker with access to the local instance to inject arbitrary files or code. This can lead to execution of malicious code within the application due to insufficient checks on resource identifiers, exposing the system to potential exploits.

Affected Version(s)

SAP Business Objects Business Intelligence Platform < 4.2

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.