CVE-2020-6245

SAP Business Objects Business Intelligence Platform, version 4.2, allows an attacker with access to local instance, to inject file or code that can be executed by the application due to Improper Control of Resource Identifiers.
Configurations

Configuration 1 (hide)

cpe:2.3:a:sap:businessobjects_business_intelligence_platform:4.2:*:*:*:*:*:*:*

History

21 Nov 2024, 05:35

Type Values Removed Values Added
References () https://launchpad.support.sap.com/#/notes/2828558 - Permissions Required () https://launchpad.support.sap.com/#/notes/2828558 - Permissions Required
References () https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=545396222 - Vendor Advisory () https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=545396222 - Vendor Advisory

Information

Published : 2020-05-12 18:15

Updated : 2024-11-21 05:35


NVD link : CVE-2020-6245

Mitre link : CVE-2020-6245

CVE.ORG link : CVE-2020-6245


JSON object : View

Products Affected

sap

  • businessobjects_business_intelligence_platform
CWE
CWE-99

Improper Control of Resource Identifiers ('Resource Injection')

CWE-74

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')