Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

CVE-2020-6222 Cross-Site Scripting (XSS) vulnerability in SAP BusinessObjects Business Intelligence Platform (Web Intelligence HTML interface), SAP security note 2880804

SAP Note 2880804
Medium priority

SAP security note 2880804, “[CVE-2020-6222] Cross-Site Scripting (XSS) vulnerability in SAP BusinessObjects Business Intelligence Platform (Web Intelligence HTML interface)”, is a note released on July 14, 2020. Below are the symptom, SAP recommended solution and reason and prerequisites.

ComponentBI-RA-WBI-FE-HTM (Business intelligence solutions > Reporting, analysis, and dashboards > Web Intelligence > Front End/Client > HTML Front End)
PriorityMedium priority
StatusReleased for Customer
Released onJuly 14, 2020

Description

Symptom

SAP BusinessObjects Business Intelligence Platform (Web Intelligence HTML interface) does not sufficiently encode user-controlled inputs, resulting in a Cross-Site Scripting (XSS) vulnerability.

Solution

User inputs are now encoded for the affected workflows.

Reason and prerequisites

To exploit this vulnerability, an attacker must trick a victim into clicking a malicious link, and the victim must have the necessary privileges to access the vulnerable page.

CVSS

Score 5.4 Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

References

Full note on SAP: SAP Support Launchpad note 2880804

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More