First published: Tue Apr 14 2020(Updated: )
The open document of SAP Business Objects Business Intelligence Platform, versions 4.1, 4.2, allows an attacker to modify certain error pages to include malicious content. This can misdirect a user who is tricked into accessing these error pages rendered by the application, leading to Content Spoofing.
Credit: cna@sap.com
Affected Software | Affected Version | How to fix |
---|---|---|
Sap Businessobjects Business Intelligence Platform | =4.1 | |
Sap Businessobjects Business Intelligence Platform | =4.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2020-6223.
The severity of CVE-2020-6223 is medium (6.1).
Versions 4.1 and 4.2 of SAP Business Objects Business Intelligence Platform are affected by CVE-2020-6223.
CVE-2020-6223 can misdirect a user who is tricked into accessing error pages rendered by the application, leading to Content Spoofing.
Yes, for more information about CVE-2020-6223, you can refer to the following links: [Link 1](https://launchpad.support.sap.com/#/notes/2878507), [Link 2](https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=544214202).