CVE-2020-6308
SAP businessobjects_business_intelligence_platform Server-Side Request Forgery (SSRF)
Record summary
CVE-2020-6308 has a selected CVSS score of 5.3 (medium); EIP currently links 4 repository PoCs and 1 Nuclei template.
Description
SAP BusinessObjects Business Intelligence Platform (Web Services) versions - 410, 420, 430, allows an unauthenticated attacker to inject arbitrary values as CMS parameters to perform lookups on the internal network which is otherwise not accessible externally. On successful exploitation, attacker can scan internal network to determine internal infrastructure and gather information for further attacks like remote file inclusion, retrieve server files, bypass firewall and force the vulnerable server to perform malicious requests, resulting in a Server-Side Request Forgery vulnerability.
Exploitation context
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
businessobjects_business_intelligence_platformBrowse SAP / businessobjects_business_intelligence_platform | VulnCheck | Version data not supplied | |
SAP BusinessObjects Business Intelligence Platform (Web Services)Browse SAP SE / SAP BusinessObjects Business Intelligence Platform (Web Services) | CVE List | < 410 | affected |
| < 420 | affected | ||
| < 430 | affected | ||
Proofs of concept
4Repository PoCs
GitHubInitRoot/CVE-2020-6308-PoCRepository PoCby InitRootStars: 36Not analyzed6 files
GitHubfreeFV/CVE-2020-6308-mass-exploiterRepository PoCby freeFVStars: 0Not analyzed2 files
GitHubTheMMMdev/CVE-2020-6308Repository PoCby TheMMMdevStars: 1Not analyzed2 files
GitHubMachadoOtto/sap_bo_launchpad-ssrf-timing_attackRepository PoCby MachadoOttoStars: 0Not analyzed3 files
Nuclei templates
1ProjectDiscoveryMEDIUMSAP BusinessObjects Business Intelligence Platform - Blind Server-Side Request ForgeryCVSS 5.3
SAP BusinessObjects Business Intelligence Platform (Web Services) 410, 420, and 430 is susceptible to blind server-side request forgery. An attacker can inject arbitrary values as CMS parameters to perform lookups on the internal network, which is otherwise not accessible externally. On successful exploitation, attacker can scan network to determine infrastructure and gather information for further attacks like remote file inclusion, retrieving server files, bypassing firewall, and forcing malicious requests.
Impact
Successful exploitation of this vulnerability could allow an attacker to send arbitrary requests from the vulnerable server, potentially leading to unauthorized access to internal resources or further attacks.
Remediation
Apply the relevant security patches provided by SAP to mitigate this vulnerability.
Source: ProjectDiscovery