Severity
9.8CRITICAL
EPSS
0.2%
top 58.66%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 14
Latest updateMay 24

Description

SAP Business Objects Business Intelligence Platform (CMC), version 4.1, 4.2, shows cleartext password in the response, leading to Information Disclosure. It involves social engineering in order to gain access to system and If password is known, it would give administrative rights to the attacker to read/modify delete the data and rights within the system.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

🔴Vulnerability Details

2
GHSA
GHSA-9w69-cmrr-7x8x: SAP Business Objects Business Intelligence Platform (CMC), version 42022-05-24
CVEList
CVE-2020-6195: SAP Business Objects Business Intelligence Platform (CMC), version 42020-04-14
CVE-2020-6195 (CRITICAL CVSS 9.8) | SAP Business Objects Business Intel | cvebase.io