Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

CVE-2020-6294 Missing Authentication check in SAP BusinessObjects Business Intelligence Platform, SAP security note 2927956

SAP Note 2927956

SAP security note 2927956, “[CVE-2020-6294] Missing Authentication Check in SAP BusinessObjects Business Intelligence Platform”. Below are the symptom and SAP recommended solution.

Description

Symptom

Xvfb of the BI platform on Unix does not perform any authentication checks for functionalities that require user identity. An attacker with access to the internal network (LAN) can connect to open ports and gain unauthenticated access to the X server. This allows the attacker to eavesdrop on the keyboard and mouse of a user, grab screenshots, and potentially capture usernames and passwords of users logged onto the remote host.

Solution

This issue is fixed in the patches listed in the “Support Package Patches” section below. Implement the Support Packages and Patches referenced by this SAP Note.

Reason and prerequisites

Issue: Missing Authentication check.

Affected Versions: SAP BusinessObjects Business Intelligence Platform 4.2 SP08, 4.2 patch 8.1, 4.2 patch 8.2, 4.2 patch 8.3, and BI 4.3 in LAN environments.

CVSS

Score 8.5 Vector: CVSS:3.0/AV:A/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N

Full note on SAP: SAP Support Launchpad note 2927956

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More