CVE-2020-6288
Last modified
CVE-2020-6288 is a medium-severity vulnerability rated 5.3/10 on the CVSS scale. SAP Business Objects Business Intelligence Platform (Web Intelligence HTML interface) allows an attacker with edit document rights to upload any file (including script files) without proper file format validation leading to Unrestricted upload of file with dangerous type vulnerability. The attacker can modify some formulas and display erroneous content. EPSS estimates a 0.66% chance of exploitation in the next 30 days.
Description
SAP Business Objects Business Intelligence Platform (Web Intelligence HTML interface) allows an attacker with edit document rights to upload any file (including script files) without proper file format validation leading to Unrestricted upload of file with dangerous type vulnerability. The attacker can modify some formulas and display erroneous content. The server is not affected only the current user browser session, that can easily be closed.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Sap | Businessobjects Business Intelligence Platform | 4.1 |
| Sap | Businessobjects Business Intelligence Platform | 4.2 |
References
- https://launchpad.support.sap.com/#/notes/2930128Permissions Required
- https://launchpad.support.sap.com/#/notes/2930128Permissions Required
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2020-6288?
How severe is CVE-2020-6288?
How do I fix CVE-2020-6288?
Are you affected by CVE-2020-6288?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
