SAP security note 2925827, “[CVE-2020-6300] Cross-Site Scripting (XSS) vulnerability in SAP Business Objects Business Intelligence Platform (Central Management Console)”. Below are the symptom and SAP recommended solution.
Description
Symptom
An attacker with Central Management Console (CMC) application administrator rights can exploit a Stored Cross-Site Scripting (XSS) vulnerability in SAP Business Objects Business Intelligence Platform’s CMC. This is due to insufficient encoding of user-controlled inputs for the RecycleBin. As a result, malicious code can be injected and executed in the context of a different end user’s browser session. While the malicious code cannot significantly impact the browser, it allows the attacker to read, modify, and send information from the victim’s browser. The victim can easily terminate the attack by closing the browser tab.
Solution
The vulnerability has been addressed by properly encoding URL parameters to prevent successful XSS attacks. This issue is fixed in the following support packages and patches:
References
CVSS
Score 4.8 Vector: CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Full note on SAP: SAP Support Launchpad note 2925827
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



