First published: Mon Jun 06 2022(Updated: )
BI Launchpad and CMC in SAP Business Objects Business Intelligence Platform, versions 4.1, 4.2, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability. Exploit is possible only when the bttoken in victim’s session is active.
Credit: cna@sap.com
Affected Software | Affected Version | How to fix |
---|---|---|
SAP Business Objects Business Intelligence Platform | =4.1 | |
SAP Business Objects Business Intelligence Platform | =4.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-6220 is a Cross-Site Scripting (XSS) vulnerability in BI Launchpad and CMC in SAP Business Objects Business Intelligence Platform versions 4.1 and 4.2.
CVE-2020-6220 has a severity rating of 4.7, which is considered medium.
The affected software versions are SAP Business Objects Business Intelligence Platform 4.1 and 4.2.
CVE-2020-6220 can be exploited by leveraging the active bttoken in the victim's session.
Yes, you can refer to the following links for more information: [SAP Note 2878507](https://launchpad.support.sap.com/#/notes/2878507) and [SAP Wiki](https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=544214202).