PT-2020-5167 · Sap · Sap Businessobjects Business Intelligence Platform

Published

2020-08-12

·

Updated

2020-08-13

·

CVE-2020-6300

CVSS v2.0

5.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions SAP Business Objects Business Intelligence Platform versions 4.2, 4.3
Description The issue exists due to insufficient protection of the web page structure, allowing a remote attacker to conduct Cross-Site Scripting (XSS) attacks. An attacker with administrator rights can use the web application to send malicious code to a different end user, as it does not sufficiently encode user-controlled inputs for RecycleBin, resulting in Stored Cross-Site Scripting (XSS).
Recommendations For versions 4.2 and 4.3, ensure that user-controlled inputs for RecycleBin are properly encoded to prevent Stored Cross-Site Scripting (XSS) attacks. As a temporary workaround, consider restricting access to the RecycleBin feature until a patch is available.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2020-05778
CVE-2020-6300

Affected Products

Sap Businessobjects Business Intelligence Platform