Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

CVE-2020-6300 Cross-Site Scripting (XSS) vulnerability in SAP Business Objects Business Intelligence Platform(Central Management Console), SAP security note 2925827

SAP Note 2925827

SAP security note 2925827, “[CVE-2020-6300] Cross-Site Scripting (XSS) vulnerability in SAP Business Objects Business Intelligence Platform (Central Management Console)”. Below are the symptom and SAP recommended solution.

Description

Symptom

An attacker with Central Management Console (CMC) application administrator rights can exploit a Stored Cross-Site Scripting (XSS) vulnerability in SAP Business Objects Business Intelligence Platform’s CMC. This is due to insufficient encoding of user-controlled inputs for the RecycleBin. As a result, malicious code can be injected and executed in the context of a different end user’s browser session. While the malicious code cannot significantly impact the browser, it allows the attacker to read, modify, and send information from the victim’s browser. The victim can easily terminate the attack by closing the browser tab.

Solution

The vulnerability has been addressed by properly encoding URL parameters to prevent successful XSS attacks. This issue is fixed in the following support packages and patches:

References

CVSS

Score 4.8 Vector: CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N

Full note on SAP: SAP Support Launchpad note 2925827

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More