First published: Tue Jul 14 2020(Updated: )
SAP Business Objects Business Intelligence Platform (BI Launchpad and CMC), versions 4.1, 4.2, allows to an attacker to embed malicious scripts in the application while uploading images, which gets executed when the victim opens these files, leading to Stored Cross Site Scripting
Credit: cna@sap.com
Affected Software | Affected Version | How to fix |
---|---|---|
Sap Businessobjects Business Intelligence Platform | =4.1 | |
Sap Businessobjects Business Intelligence Platform | =4.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2020-6278 is medium with a CVSS score of 5.4.
An attacker can exploit CVE-2020-6278 by embedding malicious scripts in the application while uploading images, which get executed when the victim opens these files, leading to Stored Cross Site Scripting.
Versions 4.1 and 4.2 of SAP Business Objects Business Intelligence Platform are affected by CVE-2020-6278.
The Common Weakness Enumeration (CWE) ID for CVE-2020-6278 is 79.
You can find more information about CVE-2020-6278 on the SAP support portal note 2912708 and the SAP Community Network (SCN) wiki page.