CVE-2020-6312: XSS
SAP BusinessObjects Business Intelligence Platform (Web Intelligence HTML interface), versions - 4.1, 4.2, allows an attacker with a non-administrative user account that can edit certain web page properties, can modify how a browser processes particular page elements, leading to stored Cross Site Scripting. In certain situations, when a user accesses an affected web page element, the attacker will be able to access or modify metadata for which they are not authorized.
Affected Software
Event History
Frequently Asked Questions
What is the CVE ID for this vulnerability?
The CVE ID for this vulnerability is CVE-2020-6312.
What is the severity of CVE-2020-6312?
The severity of CVE-2020-6312 is medium with a CVSS score of 5.4.
Which versions of SAP BusinessObjects Business Intelligence Platform are affected by CVE-2020-6312?
Versions 4.1 and 4.2 of SAP BusinessObjects Business Intelligence Platform are affected by CVE-2020-6312.
How can an attacker exploit CVE-2020-6312?
An attacker with a non-administrative user account that can edit certain web page properties can modify how a browser processes particular page elements, leading to stored Cross Site Scripting (XSS) vulnerabilities.
How can I fix CVE-2020-6312?
Apply the necessary patches and updates provided by SAP to mitigate the vulnerability in SAP BusinessObjects Business Intelligence Platform.