CVE-2020-6220: XSS
BI Launchpad and CMC in SAP Business Objects Business Intelligence Platform, versions 4.1, 4.2, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability. Exploit is possible only when the bttoken in victim’s session is active.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-6220?
CVE-2020-6220 is a Cross-Site Scripting (XSS) vulnerability in BI Launchpad and CMC in SAP Business Objects Business Intelligence Platform versions 4.1 and 4.2.
How severe is CVE-2020-6220?
CVE-2020-6220 has a severity rating of 4.7, which is considered medium.
Which software versions are affected by CVE-2020-6220?
The affected software versions are SAP Business Objects Business Intelligence Platform 4.1 and 4.2.
How can CVE-2020-6220 be exploited?
CVE-2020-6220 can be exploited by leveraging the active bttoken in the victim's session.
Are there any references available for CVE-2020-6220?
Yes, you can refer to the following links for more information: [SAP Note 2878507](https://launchpad.support.sap.com/#/notes/2878507) and [SAP Wiki](https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=544214202).