SAP security note 2905836, "[CVE-2020-6269] Information Disclosure in SAP Business Objects Business Intelligence Platform". Below are the symptom and SAP recommended solution.
Description
Symptom
Under certain conditions, SAP Business Objects allows an attacker to access information which would otherwise be restricted.
Some well-known impacts of Information Disclosure are:
- Loss of information and system configuration confidentiality
- Information gathering for further exploits and attacks
Solution
SAP Business Objects no longer discloses sensitive information. This issue is fixed in the patches listed in the “Support Package Patches” section below. For Business Intelligence Platform maintenance schedule and strategy, see the Knowledge Base Article 2144559 in the References section.
CVSS
Score 4.3 Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
References
Full note on SAP: SAP Support Launchpad note 2905836
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
