Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

CVE-2020-6216 Cross-Site Scripting (XSS) vulnerability in SAP Business Objects Business Intelligence Platform (BILaunchpad/ Opendocument), SAP security note 2876059

SAP Note 2876059
SAP Security Note
Medium priority

SAP security note 2876059, "[CVE-2020-6216] Cross-Site Scripting (XSS) vulnerability in SAP Business Objects Business Intelligence Platform (BILaunchpad/Opendocument)", is a program error note released on April 14, 2020. Below are the symptom and SAP recommended solution.

CategoryProgram error
PriorityCorrection with medium priority
TypeSAP Security Note
StatusReleased for Customer
Released onApril 14, 2020

Description

Symptom

A Reflected Cross-Site Scripting (XSS) vulnerability has been identified in the SAP Business Objects Business Intelligence Platform (BILaunchpad/Opendocument). This vulnerability arises because the application does not sufficiently encode user-controlled inputs, allowing attackers to inject malicious scripts.

Exploiting this vulnerability can lead to:

  • Defacement or modification of displayed web content.
  • Theft of user authentication information, including session data.
  • Impersonation of users to access information with their privileges.

Solution

SAP has addressed this issue by properly encoding URL parameters to prevent XSS attacks. The vulnerability is fixed in the corresponding support packages referenced by this SAP Note.

CVSS

Score 6.1

References

  • CVE-2020-6216
  • SAP Note 2144559 – Business Intelligence Platform maintenance strategy and schedule

Full note on SAP: SAP Support Launchpad note 2876059

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More