CVE-2020-6195

SAP Business Objects Business Intelligence Platform (CMC), version 4.1, 4.2, shows cleartext password in the response, leading to Information Disclosure. It involves social engineering in order to gain access to system and If password is known, it would give administrative rights to the attacker to read/modify delete the data and rights within the system.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:sap:businessobjects_business_intelligence_platform:4.1:-:*:*:*:*:*:*
cpe:2.3:a:sap:businessobjects_business_intelligence_platform:4.2:-:*:*:*:*:*:*

History

21 Nov 2024, 05:35

Type Values Removed Values Added
References () https://launchpad.support.sap.com/#/notes/2878507 - Permissions Required, Vendor Advisory () https://launchpad.support.sap.com/#/notes/2878507 - Permissions Required, Vendor Advisory
References () https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=544214202 - Vendor Advisory () https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=544214202 - Vendor Advisory

Information

Published : 2020-04-14 20:15

Updated : 2024-11-21 05:35


NVD link : CVE-2020-6195

Mitre link : CVE-2020-6195

CVE.ORG link : CVE-2020-6195


JSON object : View

Products Affected

sap

  • businessobjects_business_intelligence_platform
CWE
CWE-319

Cleartext Transmission of Sensitive Information

CWE-522

Insufficiently Protected Credentials