Improper Resource Identifier Control in SAP Business Objects Platform
CVE-2020-6245
6.5MEDIUM
Key Information:
- Vendor
- SAP
- Vendor
- CVE Published:
- 12 May 2020
Summary
The SAP Business Objects Business Intelligence Platform version 4.2 is susceptible to a vulnerability that allows an authenticated attacker with access to the local instance to inject arbitrary files or code. This can lead to execution of malicious code within the application due to insufficient checks on resource identifiers, exposing the system to potential exploits.
Affected Version(s)
SAP Business Objects Business Intelligence Platform < 4.2
References
CVSS V3.1
Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved