Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

CVE-2020-6227 Remote unauthenticated log injection in SAP Business Objects Business Intelligence Platform (CMS / Auditing issues), SAP security note 2863396

SAP Note 2863396
Medium priority

SAP security note 2863396, “[CVE-2020-6227] Remote unauthenticated log injection in SAP Business Objects Business Intelligence Platform (CMS / Auditing issues)”, was released on April 14, 2020. Below are the symptom, SAP recommended solution and the affected software components.

ComponentBusiness Intelligence Solutions > Business Intelligence Platform > CMS / Auditing issues (excl. 3rd Party Authentication)
PriorityMedium priority
StatusReleased for Customer
Released onApril 14, 2020

Description

Symptom

SAP BusinessObjects Business Intelligence Platform allows an attacker to create specially crafted GIOP packets to all SAP BO services without authentication. This vulnerability can enable the attacker to forge additional entries in the log files.

Solution

This issue is fixed in the patches listed in the “Support Package Patches” section below. Applying these patches will remediate the improper input validation vulnerability.

For more details on the Business Intelligence Platform maintenance schedule and strategy, refer to Knowledge Base Article 2144559.

Reason and prerequisites

SAP BO Services do not correctly sanitize the content of the first sequence of GIOP packets.

CVSS

Score 5.3 Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

Affected components

  • ENTERPRISE (versions 420, 430)

Full note on SAP: SAP Support Launchpad note 2863396

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More