SAP Security Note
Medium priority
SAP security note 2876059, "[CVE-2020-6216] Cross-Site Scripting (XSS) vulnerability in SAP Business Objects Business Intelligence Platform (BILaunchpad/Opendocument)", is a program error note released on April 14, 2020. Below are the symptom and SAP recommended solution.
Description
Symptom
A Reflected Cross-Site Scripting (XSS) vulnerability has been identified in the SAP Business Objects Business Intelligence Platform (BILaunchpad/Opendocument). This vulnerability arises because the application does not sufficiently encode user-controlled inputs, allowing attackers to inject malicious scripts.
Exploiting this vulnerability can lead to:
- Defacement or modification of displayed web content.
- Theft of user authentication information, including session data.
- Impersonation of users to access information with their privileges.
Solution
SAP has addressed this issue by properly encoding URL parameters to prevent XSS attacks. The vulnerability is fixed in the corresponding support packages referenced by this SAP Note.
CVSS
Score 6.1
References
- CVE-2020-6216
- SAP Note 2144559 – Business Intelligence Platform maintenance strategy and schedule
Full note on SAP: SAP Support Launchpad note 2876059
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
