Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

CVE-2020-6189 Information Disclosure in SAP BusinessObjects BI Central Management Console, SAP security note 2695210

SAP Note 2695210

SAP security note 2695210, "[CVE-2020-6189] Information Disclosure in SAP BusinessObjects BI Central Management Console". Below are the symptom, SAP recommended solution and the affected software components.

Description

Symptom

Under certain conditions, the Central Management Console (CMC) in SAP BusinessObjects BI allows an attacker to access sensitive enterprise private-network information that should otherwise be restricted. This Information Disclosure vulnerability can lead to:

  • Loss of information and system configuration confidentiality
  • Information gathering for further exploits and attacks

Solution

SAP has addressed this issue by updating error messages to prevent the disclosure of sensitive information. Additionally, a new configuration page has been introduced to allow administrators to set up a whitelist of authorized URLs for use in the CMC settings pages.

This vulnerability is fixed in the patches listed below. For the latest patch levels, refer to the “Support Packages & Patches” section.

Reason and prerequisites

In the CMC, specific settings pages generate error messages that reveal excessive network-related information, facilitating enumeration by attackers.

CVSS

Score 5.3 Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

References

Affected components

  • ENTERPRISE
  • Business Intelligence Solutions > Reporting, Analysis, and Dashboards > Web Intelligence > Front End/Client > HTML Front End

Full note on SAP: SAP Support Launchpad note 2695210

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More