SAP security note 2927956, “[CVE-2020-6294] Missing Authentication Check in SAP BusinessObjects Business Intelligence Platform”. Below are the symptom and SAP recommended solution.
Description
Symptom
Xvfb of the BI platform on Unix does not perform any authentication checks for functionalities that require user identity. An attacker with access to the internal network (LAN) can connect to open ports and gain unauthenticated access to the X server. This allows the attacker to eavesdrop on the keyboard and mouse of a user, grab screenshots, and potentially capture usernames and passwords of users logged onto the remote host.
Solution
This issue is fixed in the patches listed in the “Support Package Patches” section below. Implement the Support Packages and Patches referenced by this SAP Note.
Reason and prerequisites
Issue: Missing Authentication check.
Affected Versions: SAP BusinessObjects Business Intelligence Platform 4.2 SP08, 4.2 patch 8.1, 4.2 patch 8.2, 4.2 patch 8.3, and BI 4.3 in LAN environments.
CVSS
Score 8.5 Vector: CVSS:3.0/AV:A/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N
Full note on SAP: SAP Support Launchpad note 2927956
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
