First published: Tue Apr 14 2020(Updated: )
SAP Business Objects Business Intelligence Platform (BI Launchpad), version 4.2, does not sufficiently encode user-controlled inputs, resulting in reflected Cross-Site Scripting (XSS) vulnerability.
Credit: cna@sap.com
Affected Software | Affected Version | How to fix |
---|---|---|
Sap Businessobjects Business Intelligence Platform | =4.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-6216 is a Cross-Site Scripting (XSS) vulnerability in SAP Business Objects Business Intelligence Platform (BI Launchpad) version 4.2.
CVE-2020-6216 allows an attacker to perform reflected Cross-Site Scripting (XSS) attacks on the BI Launchpad 4.2, potentially compromising user data and session information.
CVE-2020-6216 has a severity rating of medium with a CVSS score of 6.1.
To fix CVE-2020-6216, it is recommended to apply the latest patch or update provided by SAP Business Objects to address the Cross-Site Scripting vulnerability.
More information about CVE-2020-6216 can be found in the SAP support notes at https://launchpad.support.sap.com/#/notes/2876059 and the SAP Community Network wiki at https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=544214202.