CVE-2020-6308
Summary
| CVE | CVE-2020-6308 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-10-20 14:15:00 UTC |
| Updated | 2020-10-22 12:29:00 UTC |
| Description | SAP BusinessObjects Business Intelligence Platform (Web Services) versions - 410, 420, 430, allows an unauthenticated attacker to inject arbitrary values as CMS parameters to perform lookups on the internal network which is otherwise not accessible externally. On successful exploitation, attacker can scan internal network to determine internal infrastructure and gather information for further attacks like remote file inclusion, retrieve server files, bypass firewall and force the vulnerable server to perform malicious requests, resulting in a Server-Side Request Forgery vulnerability. |
Risk And Classification
Problem Types: CWE-918
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Sap | Businessobjects Business Intelligence Platform | 4.1 | - | All | All |
| Application | Sap | Businessobjects Business Intelligence Platform | 4.2 | - | All | All |
| Application | Sap | Businessobjects Business Intelligence Platform | 4.3 | All | All | All |
| Application | Sap | Businessobjects Business Intelligence Platform | 4.1 | - | All | All |
| Application | Sap | Businessobjects Business Intelligence Platform | 4.2 | - | All | All |
| Application | Sap | Businessobjects Business Intelligence Platform | 4.3 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| SAP Security Patch Day – October 2020 - Product Security Response at SAP - Community Wiki | MISC | wiki.scn.sap.com | Vendor Advisory |
| launchpad.support.sap.com | MISC | launchpad.support.sap.com | Permissions Required, Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.