Medium priority
SAP security note 2828558, "[CVE-2020-6245] Multiple Vulnerabilities in SAP Business Objects Business Intelligence Platform", is released on May 12, 2020. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
This SAP Security Note addresses multiple vulnerabilities identified in the SAP Business Objects Business Intelligence Platform. Below are the details of each vulnerability, their impacts, and the recommended solutions.
- File Injection (CVE-2020-6245, CVSS 6.5, Vector: CVSS:3.0/AV:L/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H): unauthorized execution of commands, sensitive information disclosure, denial of service.
- Denial of Service (DoS) (CVE-2020-6247, CVSS 5.9, Vector: CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H): service interruptions and degraded performance, direct impact on system availability.
- Information Disclosure (CVE-2020-6251, CVSS 4.3, Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N): loss of information and system configuration confidentiality, information gathering for further exploits and attacks.
Solution
- File Injection & Information Disclosure: implement validation of message sizes during packet unmarshalling; ensure proper error handling to prevent unauthorized access and information leaks.
- Denial of Service: validate actual message sizes against given sizes to prevent system crashes or flooding of the Central Management Server.
Affected components
- ENTERPRISE 4.20
- ENTERPRISE 4.30
Full note on SAP: SAP Support Launchpad note 2828558
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
