SAP Business Objects Business Intelligence Platform, version 4.2, allows an attacker with access to local instance, to inject file or code that can be executed by the application due to Improper Control of Resource Identifiers.
References
Link | Resource |
---|---|
https://launchpad.support.sap.com/#/notes/2828558 | Permissions Required |
https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=545396222 | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
Information
Published : 2020-05-12 11:15
Updated : 2020-05-14 12:03
NVD link : CVE-2020-6245
Mitre link : CVE-2020-6245
JSON object : View
CWE
CWE-74
Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
Products Affected
sap
- businessobjects_business_intelligence_platform