Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

CVE-2020-6368 Cross-Site Scripting (XSS) vulnerability in SAP Business Planning and Consolidation, SAP security note 2960825

SAP Note 2960825

SAP security note 2960825, “[CVE-2020-6368] Cross-Site Scripting (XSS) vulnerability in SAP Business Planning and Consolidation”. Below are the symptom, SAP recommended solution and the affected software components.

Description

Symptom

SAP Business Planning and Consolidation can be abused by an attacker, allowing them to modify displayed application content without authorization and potentially obtain authentication information from other legitimate users.

Solution

The data is now properly encoded to prevent a successful XSS attack. Implement the correction instructions or upgrade to the corresponding Support Packages referenced by this SAP Note. Note that the vulnerability does not exist in the cloud version.

Reason and prerequisites

Reason: Missing input validation and insufficient encoding.

CVSS

Score 5.4 Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

Affected components

  • BPC4HANA: Versions 100 to 200
  • SAP_BW: Versions 750 to 755
  • CPMBPC: Version 810

Full note on SAP: SAP Support Launchpad note 2960825

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More