Medium priority
SAP security note 2880804, “[CVE-2020-6222] Cross-Site Scripting (XSS) vulnerability in SAP BusinessObjects Business Intelligence Platform (Web Intelligence HTML interface)”, is a note released on July 14, 2020. Below are the symptom, SAP recommended solution and reason and prerequisites.
Description
Symptom
SAP BusinessObjects Business Intelligence Platform (Web Intelligence HTML interface) does not sufficiently encode user-controlled inputs, resulting in a Cross-Site Scripting (XSS) vulnerability.
Solution
User inputs are now encoded for the affected workflows.
Reason and prerequisites
To exploit this vulnerability, an attacker must trick a victim into clicking a malicious link, and the victim must have the necessary privileges to access the vulnerable page.
CVSS
Score 5.4 Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
References
Full note on SAP: SAP Support Launchpad note 2880804
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
