Cross-Site Scripting in SAP Business Objects BI Platform
CVE-2020-6257

5.4MEDIUM

Key Information:

Summary

The SAP Business Objects Business Intelligence Platform version 4.2 is vulnerable to Cross-Site Scripting due to inadequate encoding of user-controlled inputs. This could allow attackers to inject malicious scripts, potentially compromising user data and system integrity. Organizations using this platform should assess their exposure and apply necessary security measures.

Affected Version(s)

SAP Business Objects Business Intelligence Platform (CMC and BI launchpad) < 4.2

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.