CVE-2020-6245 PUBLISHED CVSS 6.5 MEDIUM

SAP Business Objects Business Intelligence Platform, version 4.2, allows an attacker with access to local instance, to inject file or code that can be executed by the application due to Improper Control of Resource Identifiers.

EPSS 0.05% · 17.0th percentile

Risk Scores

CVSS v3.0
6.5
CVSS:3.0/AV:L/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H
EPSS Score
0.05%
17.0th percentile

Affected Products

VendorProductVersions
SAP SESAP Business Objects Business Intelligence Platform< 4.2
sapbusinessobjects_business_intelligence_platform4.2

Timeline

References

Open in Interactive Console →