Record summary

CVE-2020-6308 has a selected CVSS score of 5.3 (medium); EIP currently links 4 repository PoCs and 1 Nuclei template.

Description

SAP BusinessObjects Business Intelligence Platform (Web Services) versions - 410, 420, 430, allows an unauthenticated attacker to inject arbitrary values as CMS parameters to perform lookups on the internal network which is otherwise not accessible externally. On successful exploitation, attacker can scan internal network to determine internal infrastructure and gather information for further attacks like remote file inclusion, retrieve server files, bypass firewall and force the vulnerable server to perform malicious requests, resulting in a Server-Side Request Forgery vulnerability.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Feb 14, 2024 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Repository PoCs
4
Nuclei templates
1

Affected products and versions

2
ProductSourceVersion rangeStatus

businessobjects_business_intelligence_platform

Browse SAP / businessobjects_business_intelligence_platform
VulnCheckVersion data not supplied

SAP BusinessObjects Business Intelligence Platform (Web Services)

Browse SAP SE / SAP BusinessObjects Business Intelligence Platform (Web Services)
CVE List< 410affected
< 420affected
< 430affected

Proofs of concept

4

Repository PoCs

GitHubInitRoot/CVE-2020-6308-PoCRepository PoCby InitRootStars: 36Not analyzed6 files

455.5 KiB

GitHub

PoC details
GitHubfreeFV/CVE-2020-6308-mass-exploiterRepository PoCby freeFVStars: 0Not analyzed2 files

2.5 KiB

GitHub

PoC details
GitHubTheMMMdev/CVE-2020-6308Repository PoCby TheMMMdevStars: 1Not analyzed2 files

4.1 KiB

GitHub

PoC details
GitHubMachadoOtto/sap_bo_launchpad-ssrf-timing_attackRepository PoCby MachadoOttoStars: 0Not analyzed3 files

5.2 KiB

GitHub

PoC details

Nuclei templates

1
ProjectDiscoveryMEDIUMSAP BusinessObjects Business Intelligence Platform - Blind Server-Side Request ForgeryCVSS 5.3

SAP BusinessObjects Business Intelligence Platform (Web Services) 410, 420, and 430 is susceptible to blind server-side request forgery. An attacker can inject arbitrary values as CMS parameters to perform lookups on the internal network, which is otherwise not accessible externally. On successful exploitation, attacker can scan network to determine infrastructure and gather information for further attacks like remote file inclusion, retrieving server files, bypassing firewall, and forcing malicious requests.

Impact

Successful exploitation of this vulnerability could allow an attacker to send arbitrary requests from the vulnerable server, potentially leading to unauthorized access to internal resources or further attacks.

Remediation

Apply the relevant security patches provided by SAP to mitigate this vulnerability.

WeaknessesCWE-918
Authorsmadrobot
Template tagscve2020cvesapssrfoastunauthvkevvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CPE: cpe:2.3:a:sap:businessobjects_business_intelligence_platform:4.1:-:*:*:*:*:*:*

Source: ProjectDiscovery

References

3