CVE-2020-6300: XSS
SAP Business Objects Business Intelligence Platform (Central Management Console), versions- 4.2, 4.3, allows an attacker with administrator rights can use the web application to send malicious code to a different end user (victim), as it does not sufficiently encode user-controlled inputs for RecycleBin, resulting in Stored Cross-Site Scripting (XSS) vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this SAP Business Objects Business Intelligence Platform vulnerability?
The vulnerability ID for this SAP Business Objects Business Intelligence Platform vulnerability is CVE-2020-6300.
What is the severity of CVE-2020-6300?
The severity of CVE-2020-6300 is medium with a severity value of 4.8.
What is the affected version of SAP Business Objects Business Intelligence Platform?
The affected versions of SAP Business Objects Business Intelligence Platform are 4.2 and 4.3.
What actions can an attacker with administrator rights perform in this vulnerability?
An attacker with administrator rights can use the web application to send malicious code to a different end user (victim) in this vulnerability.
How can I fix CVE-2020-6300 in SAP Business Objects Business Intelligence Platform?
To fix CVE-2020-6300 in SAP Business Objects Business Intelligence Platform, apply the necessary security patches provided by SAP.