cbcvebase.
CVE-2020-6222
published 2020-04-14

CVE-2020-6222: SAP Business Objects Business Intelligence Platform (Web Intelligence HTML interface), versions 4.1, 4.2, does not sufficiently encode user-controlled inputs…

medium5.4CVSS 3.1
AVNACLPRLUIRSCCLILAN
SAP Business Objects Business Intelligence Platform (Web Intelligence HTML interface), versions 4.1, 4.2, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability.

Affected

4 ranges
VendorProductVersion rangeFixed in
sapbusinessobjects_business_intelligence_platform
sapbusinessobjects_business_intelligence_platform
sap_sesap_businessobjects_business_intelligence_platform< 4.14.1
sap_sesap_businessobjects_business_intelligence_platform< 4.24.2