CVE-2020-6237

HIGH

SAP Business Objects <4.3 - Info Disclosure

Title source: llm
STIX 2.1

Description

Under certain conditions, SAP Business Objects Business Intelligence Platform, version 4.1, 4.2, dswsbobje web application allows an attacker to access information which would otherwise be restricted, leading to Information Disclosure.

References (2)

Core 2
Core References
Permissions Required, Vendor Advisory x_refsource_misc
https://launchpad.support.sap.com/#/notes/2898077

Scores

CVSS v3 7.5
EPSS 0.0035
EPSS Percentile 57.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Details

Status published
Products (2)
sap/businessobjects_business_intelligence_platform 4.1
sap/businessobjects_business_intelligence_platform 4.2
Published Apr 14, 2020
Tracked Since Feb 18, 2026