CVE-2020-6223

MEDIUM

SAP BusinessObjects Business Intelligence Platform 4.1-4.2 - Content Spoofing via Error Page Modification

Title source: llm
STIX 2.1

Description

The open document of SAP Business Objects Business Intelligence Platform, versions 4.1, 4.2, allows an attacker to modify certain error pages to include malicious content. This can misdirect a user who is tricked into accessing these error pages rendered by the application, leading to Content Spoofing.

References (2)

Core 2
Core References
Permissions Required, Vendor Advisory x_refsource_misc
https://launchpad.support.sap.com/#/notes/2878507

Scores

CVSS v3 6.1
EPSS 0.0022
EPSS Percentile 44.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Details

CWE
CWE-601
Status published
Products (2)
sap/businessobjects_business_intelligence_platform 4.1
sap/businessobjects_business_intelligence_platform 4.2
Published Apr 14, 2020
Tracked Since Feb 18, 2026