First published: Tue Apr 14 2020(Updated: )
SAP Business Objects Business Intelligence Platform (Web Intelligence HTML interface), versions 4.1, 4.2, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability.
Credit: cna@sap.com
Affected Software | Affected Version | How to fix |
---|---|---|
Sap Businessobjects Business Intelligence Platform | =4.1 | |
Sap Businessobjects Business Intelligence Platform | =4.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2020-6222.
The severity rating for CVE-2020-6222 is medium (5.4).
CVE-2020-6222 allows Cross-Site Scripting (XSS) attacks on SAP Business Objects Business Intelligence Platform versions 4.1 and 4.2.
To fix the CVE-2020-6222 vulnerability, update SAP Business Objects Business Intelligence Platform to a patched version. References to the patches can be found at https://launchpad.support.sap.com/#/notes/2880804 and https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=544214202.
The CWE ID for CVE-2020-6222 is CWE-79 (Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')).