Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

CVE-2020-6281 Cross-Site Scripting (XSS) vulnerability in SAP Business Objects Business Intelligence Platform(BI Launch pad), SAP security note 2917743

SAP Note 2917743

SAP security note 2917743, “[CVE-2020-6281] Cross-Site Scripting (XSS) Vulnerability in SAP Business Objects Business Intelligence Platform (BI Launchpad)”, is a note. Below are the symptom and SAP recommended solution.

Description

Symptom

Custom libraries of SAP Business Objects Business Intelligence Platform (BI Launchpad) do not sufficiently encode user-controlled inputs, resulting in a Cross-Site Scripting (XSS) vulnerability.

Solution

URL parameters are now properly encoded using SAP provided API.

CVSS

Score 6.1 Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

References

Full note on SAP: SAP Support Launchpad note 2917743

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More