PT-2020-5167 · Sap · Sap Businessobjects Business Intelligence Platform
Published
2020-08-12
·
Updated
2020-08-13
·
CVE-2020-6300
CVSS v2.0
5.5
Medium
| Vector | AV:N/AC:L/Au:S/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
SAP Business Objects Business Intelligence Platform versions 4.2, 4.3
Description
The issue exists due to insufficient protection of the web page structure, allowing a remote attacker to conduct Cross-Site Scripting (XSS) attacks. An attacker with administrator rights can use the web application to send malicious code to a different end user, as it does not sufficiently encode user-controlled inputs for
RecycleBin, resulting in Stored Cross-Site Scripting (XSS).Recommendations
For versions 4.2 and 4.3, ensure that user-controlled inputs for
RecycleBin are properly encoded to prevent Stored Cross-Site Scripting (XSS) attacks. As a temporary workaround, consider restricting access to the RecycleBin feature until a patch is available.Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sap Businessobjects Business Intelligence Platform