Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

CVE-2020-6237 Information Disclosure in SAP Business Objects Business Intelligence Platform (dswsbobje Web Application), SAP security note 2898077

SAP Note 2898077

SAP security note 2898077, "[CVE-2020-6237] Information Disclosure in SAP Business Objects Business Intelligence Platform (dswsbobje Web Application)". Below are the symptom and SAP recommended solution.

Description

Symptom

UPDATE 13th October 2020: This note has been re-released with updated 'Support Packages & Patches' information. For the release SBOP BI PLATFORM SERVERS 4.2, we added the Patch level 001000 under SP007.

Under certain conditions, the SAP Business Objects – dswsbobje web application allows an attacker to access information which would otherwise be restricted.

Some well-known impacts of Information Disclosure are:

  • Loss of information and system configuration confidentiality
  • Information gathering for further exploits and attacks, e.g., Denial of Service

Solution

The affected system components no longer reveal internal information to non-authenticated users.

This issue is fixed in the patches listed in the Support Packages and Patches section below.

The Support Packages and Patches section will be populated with the relevant patch levels once they are released.

For Business Intelligence Platform maintenance schedule and strategy, see the Knowledge Base Article 2144559 in the References section.

CVSS

Score 7.5 Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

References

Full note on SAP: SAP Support Launchpad note 2898077

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More