Stored Cross Site Scripting Vulnerability in SAP BusinessObjects Business Intelligence Platform
CVE-2020-6312
5.4MEDIUM
Key Information:
- Vendor
SAP
- Vendor
- CVE Published:
- 9 September 2020
What is CVE-2020-6312?
The SAP BusinessObjects Business Intelligence Platform's Web Intelligence HTML interface is susceptible to stored Cross Site Scripting when certain web page properties are edited by a non-administrative user. This vulnerability allows attackers to manipulate how a browser interprets various page elements, potentially leading to unauthorized access or modification of metadata when users interact with affected web elements.
Affected Version(s)
SAP BusinessObjects Business Intelligence Platform (Web Intelligence HTML interface) < 4.1 < 4.1
SAP BusinessObjects Business Intelligence Platform (Web Intelligence HTML interface) < 4.2 < 4.2