CVE-2020-6288

MEDIUM

SAP Business Objects - Unrestricted File Upload

Title source: llm
STIX 2.1

Description

SAP Business Objects Business Intelligence Platform (Web Intelligence HTML interface) allows an attacker with edit document rights to upload any file (including script files) without proper file format validation leading to Unrestricted upload of file with dangerous type vulnerability. The attacker can modify some formulas and display erroneous content. The server is not affected only the current user browser session, that can easily be closed.

References (2)

Core 2
Core References
Permissions Required x_refsource_misc
https://launchpad.support.sap.com/#/notes/2930128

Scores

CVSS v3 5.3
EPSS 0.0022
EPSS Percentile 44.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

Details

CWE
CWE-434
Status published
Products (2)
sap/businessobjects_business_intelligence_platform 4.1
sap/businessobjects_business_intelligence_platform 4.2
Published Sep 09, 2020
Tracked Since Feb 18, 2026