Medium priority
SAP security note 2863396, “[CVE-2020-6227] Remote unauthenticated log injection in SAP Business Objects Business Intelligence Platform (CMS / Auditing issues)”, was released on April 14, 2020. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
SAP BusinessObjects Business Intelligence Platform allows an attacker to create specially crafted GIOP packets to all SAP BO services without authentication. This vulnerability can enable the attacker to forge additional entries in the log files.
Solution
This issue is fixed in the patches listed in the “Support Package Patches” section below. Applying these patches will remediate the improper input validation vulnerability.
For more details on the Business Intelligence Platform maintenance schedule and strategy, refer to Knowledge Base Article 2144559.
Reason and prerequisites
SAP BO Services do not correctly sanitize the content of the first sequence of GIOP packets.
CVSS
Score 5.3 Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Affected components
- ENTERPRISE (versions 420, 430)
Full note on SAP: SAP Support Launchpad note 2863396
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
