Cross-Site Scripting in SAP Business Objects BI Platform
CVE-2020-6257
5.4MEDIUM
Key Information:
- Vendor
- SAP
- Vendor
- CVE Published:
- 12 May 2020
Summary
The SAP Business Objects Business Intelligence Platform version 4.2 is vulnerable to Cross-Site Scripting due to inadequate encoding of user-controlled inputs. This could allow attackers to inject malicious scripts, potentially compromising user data and system integrity. Organizations using this platform should assess their exposure and apply necessary security measures.
Affected Version(s)
SAP Business Objects Business Intelligence Platform (CMC and BI launchpad) < 4.2
References
CVSS V3.1
Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved