Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

CVE-2020-6245 Multiple Vulnerabilities in SAP Business Objects Business Intelligence Platform, SAP security note 2828558

SAP Note 2828558
Medium priority

SAP security note 2828558, "[CVE-2020-6245] Multiple Vulnerabilities in SAP Business Objects Business Intelligence Platform", is released on May 12, 2020. Below are the symptom, SAP recommended solution and the affected software components.

ComponentBI-BIP-LCM (Business Intelligence Platform Lifecycle Management Console – Promotion Management, Version Management)
PriorityCorrection with medium priority
StatusReleased for Customer
Released onMay 12, 2020
LanguageEnglish

Description

Symptom

This SAP Security Note addresses multiple vulnerabilities identified in the SAP Business Objects Business Intelligence Platform. Below are the details of each vulnerability, their impacts, and the recommended solutions.

  • File Injection (CVE-2020-6245, CVSS 6.5, Vector: CVSS:3.0/AV:L/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H): unauthorized execution of commands, sensitive information disclosure, denial of service.
  • Denial of Service (DoS) (CVE-2020-6247, CVSS 5.9, Vector: CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H): service interruptions and degraded performance, direct impact on system availability.
  • Information Disclosure (CVE-2020-6251, CVSS 4.3, Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N): loss of information and system configuration confidentiality, information gathering for further exploits and attacks.

Solution

  • File Injection & Information Disclosure: implement validation of message sizes during packet unmarshalling; ensure proper error handling to prevent unauthorized access and information leaks.
  • Denial of Service: validate actual message sizes against given sizes to prevent system crashes or flooding of the Central Management Server.

Affected components

  • ENTERPRISE 4.20
  • ENTERPRISE 4.30

Full note on SAP: SAP Support Launchpad note 2828558

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More