SAP Business Objects Business Intelligence Platform (CMC), version 4.1, 4.2, shows cleartext password in the response, leading to Information Disclosure. It involves social engineering in order to gain access to system and If password is known, it would give administrative rights to the attacker to read/modify delete the data and rights within the system.
References
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: sap

Published: 2020-04-14T19:36:32

Updated: 2020-04-14T19:36:32

Reserved: 2020-01-08T00:00:00


Link: CVE-2020-6195

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2020-04-14T20:15:15.137

Modified: 2021-07-21T11:39:23.747


Link: CVE-2020-6195

JSON object: View

cve-icon Redhat Information

No data.