CVE-2020-6245

MEDIUM

SAP BusinessObjects <4.2 - Code Injection

Title source: llm
STIX 2.1

Description

SAP Business Objects Business Intelligence Platform, version 4.2, allows an attacker with access to local instance, to inject file or code that can be executed by the application due to Improper Control of Resource Identifiers.

References (2)

Core 2
Core References
Permissions Required x_refsource_misc
https://launchpad.support.sap.com/#/notes/2828558

Scores

CVSS v3 6.7
EPSS 0.0005
EPSS Percentile 17.0%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-99 CWE-74
Status published
Products (1)
sap/businessobjects_business_intelligence_platform 4.2
Published May 12, 2020
Tracked Since Feb 18, 2026