SAP Business Objects Business Intelligence Platform (Web Intelligence HTML interface) allows an attacker with edit document rights to upload any file (including script files) without proper file format validation leading to Unrestricted upload of file with dangerous type vulnerability. The attacker can modify some formulas and display erroneous content. The server is not affected only the current user browser session, that can easily be closed.
References
Link | Resource |
---|---|
https://launchpad.support.sap.com/#/notes/2930128 | Permissions Required |
https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=557449700 | Vendor Advisory |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: sap
Published: 2020-09-09T12:52:41
Updated: 2020-09-09T12:52:41
Reserved: 2020-01-08T00:00:00
Link: CVE-2020-6288
JSON object: View
NVD Information
Status : Analyzed
Published: 2020-09-09T13:15:11.487
Modified: 2020-09-10T02:03:25.297
Link: CVE-2020-6288
JSON object: View
Redhat Information
No data.
CWE