First published: Tue Apr 14 2020(Updated: )
SAP Business Objects Business Intelligence Platform (Web Intelligence HTML interface), version 4.2, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability.
Credit: cna@sap.com
Affected Software | Affected Version | How to fix |
---|---|---|
Sap Businessobjects Business Intelligence Platform | =4.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
Vulnerability CVE-2020-6226 is a Cross-Site Scripting (XSS) vulnerability in SAP Business Objects Business Intelligence Platform (Web Intelligence HTML interface) version 4.2.
Vulnerability CVE-2020-6226 allows attackers to execute malicious scripts in a victim's browser, potentially leading to unauthorized access or data theft.
Vulnerability CVE-2020-6226 has a severity rating of medium with a CVSS score of 5.4.
You can check the version of SAP Business Objects Business Intelligence Platform installed on your system to determine if it includes version 4.2, which is affected by CVE-2020-6226.
To mitigate vulnerability CVE-2020-6226, it is recommended to apply the necessary patches or updates provided by SAP.