CVE List

CVE-2020-6220

Moderate 4.7

BI Launchpad and CMC in SAP Business Objects Business Intelligence Platform, versions 4.1, 4.2, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability. Exploit is possible only when the bttoken in victim’s session is active.

Published June 6, 2022.

Affected software

Get alerts for Sap Business Objects Business Intelligence Platform

Reference links