CVE-2020-6242 PUBLISHED CVSS 9.800000190734863 CRITICAL

SAP Business Objects Business Intelligence Platform (Live Data Connect), versions 1.0, 2.0, 2.1, 2.2, 2.3, allows an attacker to logon on the Central Management Console without password in case of the BIPRWS application server was not protected with some specific certificate, leading to Missing Authentication Check.

EPSS 0.23% · 45.5th percentile

Risk Scores

CVSS v3.0
9.800000190734863
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
0.23%
45.5th percentile

Affected Products

VendorProductVersions
SAP SESAP Business Objects Business Intelligence Platform (Live Data Connect)< 1.0, < 2.0, < 2.x
sapbusinessobjects_business_intelligence_platform2.3, 1.0, 2.2

Timeline

References

Open in Interactive Console →