Cross-Site Scripting in SAP Business Objects BI Platform
CVE-2020-6257
5.4MEDIUM
Key Information:
- Vendor
SAP
- Vendor
- CVE Published:
- 12 May 2020
What is CVE-2020-6257?
The SAP Business Objects Business Intelligence Platform version 4.2 is vulnerable to Cross-Site Scripting due to inadequate encoding of user-controlled inputs. This could allow attackers to inject malicious scripts, potentially compromising user data and system integrity. Organizations using this platform should assess their exposure and apply necessary security measures.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
SAP Business Objects Business Intelligence Platform (CMC and BI launchpad) < 4.2
References
CVSS V3.1
Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved