VulnerabilityModified
CVE-2020-6269
Under certain conditions SAP Business Objects Business Intelligence Platform, version 4.2, allows an attacker to access information which would otherwise be restricted, leading to Information Disclosure.
MEDIUM 6.5EPSS 0.79%
Does this matter?
Lower severity and a low EPSS score (0.79%). Track it; it rarely justifies an emergency change on its own.
Description
Under certain conditions SAP Business Objects Business Intelligence Platform, version 4.2, allows an attacker to access information which would otherwise be restricted, leading to Information Disclosure.
- CVSS 3.1
- 6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 0.79% probability · 54th percentile
- CISA KEV
- Not listed
- Affected
- sap/businessobjects business intelligence platform
- Source
- cna@sap.com
References
- https://launchpad.support.sap.com/#/notes/2905836Permissions Required
- https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=547426775Vendor Advisory
- https://launchpad.support.sap.com/#/notes/2905836Permissions Required
- https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=547426775Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.