Stored Cross-Site Scripting Vulnerability in SAP Business Objects Business Intelligence
CVE-2020-6300

4.8MEDIUM

Key Information:

Summary

A vulnerability exists in SAP Business Objects Business Intelligence Platform's Central Management Console, where an attacker with administrator privileges can exploit insufficient encoding of user-controlled input in the RecycleBin feature. This flaw enables the execution of malicious scripts in the context of other users, potentially leading to unauthorized actions or data exposure.

Affected Version(s)

SAP Business Objects Business Intelligence Platform (Central Management Console) < 4.2 < 4.2

SAP Business Objects Business Intelligence Platform (Central Management Console) < 4.3 < 4.3

References

CVSS V3.1

Score:
4.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.