CVE-2020-6281: XSS
Published Jul 14, 2020
·Updated
SAP Business Objects Business Intelligence Platform (BI Launchpad), version 4.2, does not sufficiently encode user-controlled inputs, resulting reflected in Cross-Site Scripting.
Affected Software
1 affected component
SAP BusinessObjects Business Intelligence platform=4.2
Event History
Jul 14, 2020
CVE Published
via MITRE·12:30 PM
Data Sourced
via MITRE·12:30 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID of this SAP Business Objects Business Intelligence Platform vulnerability?
The vulnerability ID is CVE-2020-6281.
2
What is the severity of CVE-2020-6281?
The severity of CVE-2020-6281 is medium with a CVSS score of 6.1.
3
How does CVE-2020-6281 affect SAP Business Objects Business Intelligence Platform?
CVE-2020-6281 affects SAP Business Objects Business Intelligence Platform version 4.2.
4
What is the impact of CVE-2020-6281?
CVE-2020-6281 allows for reflected Cross-Site Scripting (XSS) attacks.
5
How can I mitigate the vulnerability CVE-2020-6281 in SAP Business Objects Business Intelligence Platform?
To mitigate CVE-2020-6281, SAP provides security patches and recommends updating to the latest version of the platform. More details can be found in the SAP support notes.