First published: Wed Sep 09 2020(Updated: )
SAP BusinessObjects Business Intelligence Platform (Web Intelligence HTML interface), versions - 4.1, 4.2, allows an attacker with a non-administrative user account that can edit certain web page properties, can modify how a browser processes particular page elements, leading to stored Cross Site Scripting. In certain situations, when a user accesses an affected web page element, the attacker will be able to access or modify metadata for which they are not authorized.
Credit: cna@sap.com
Affected Software | Affected Version | How to fix |
---|---|---|
Sap Businessobjects Business Intelligence Platform | =4.1 | |
Sap Businessobjects Business Intelligence Platform | =4.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The CVE ID for this vulnerability is CVE-2020-6312.
The severity of CVE-2020-6312 is medium with a CVSS score of 5.4.
Versions 4.1 and 4.2 of SAP BusinessObjects Business Intelligence Platform are affected by CVE-2020-6312.
An attacker with a non-administrative user account that can edit certain web page properties can modify how a browser processes particular page elements, leading to stored Cross Site Scripting (XSS) vulnerabilities.
Apply the necessary patches and updates provided by SAP to mitigate the vulnerability in SAP BusinessObjects Business Intelligence Platform.