CVE-2020-6222: XSS
SAP Business Objects Business Intelligence Platform (Web Intelligence HTML interface), versions 4.1, 4.2, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this SAP Business Objects Business Intelligence Platform vulnerability?
The vulnerability ID is CVE-2020-6222.
What is the severity rating of CVE-2020-6222?
The severity rating for CVE-2020-6222 is medium (5.4).
How does CVE-2020-6222 affect SAP Business Objects Business Intelligence Platform?
CVE-2020-6222 allows Cross-Site Scripting (XSS) attacks on SAP Business Objects Business Intelligence Platform versions 4.1 and 4.2.
How can I fix the CVE-2020-6222 vulnerability?
To fix the CVE-2020-6222 vulnerability, update SAP Business Objects Business Intelligence Platform to a patched version. References to the patches can be found at https://launchpad.support.sap.com/#/notes/2880804 and https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=544214202.
What is the Common Weakness Enumeration (CWE) ID for CVE-2020-6222?
The CWE ID for CVE-2020-6222 is CWE-79 (Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')).