CVE-2020-14202: XSS
Published Jun 22, 2020
·Updated
WebFOCUS Business Intelligence 8.0 (SP6) was prone to XSS via arbitrary URL parameters.
Affected Software
1 affected component
ibi WebFOCUS Business Intelligence=8.0-sp6
Event History
Jun 22, 2020
CVE Published
via MITRE·12:47 PM
Data Sourced
via MITRE·12:47 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2020-14202?
CVE-2020-14202 has a medium severity level due to its potential for cross-site scripting attacks.
2
How do I fix CVE-2020-14202?
To fix CVE-2020-14202, upgrade to a version of WebFOCUS Business Intelligence that is patched against this vulnerability.
3
What type of vulnerability is CVE-2020-14202?
CVE-2020-14202 is a cross-site scripting (XSS) vulnerability caused by the handling of arbitrary URL parameters.
4
Which versions of WebFOCUS Business Intelligence are affected by CVE-2020-14202?
WebFOCUS Business Intelligence version 8.0 (SP6) is affected by CVE-2020-14202.
5
Can CVE-2020-14202 be exploited remotely?
Yes, CVE-2020-14202 can be exploited remotely by an attacker using crafted URL parameters.