SAP Business Objects Business Intelligence Platform (CMC), version 4.1, 4.2, shows cleartext password in the response, leading to Information Disclosure. It involves social engineering in order to gain access to system and If password is known, it would give administrative rights to the attacker to read/modify delete the data and rights within the system.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: sap

Published: 2020-04-14T19:36:32

Updated: 2024-08-04T08:55:22.152Z

Reserved: 2020-01-08T00:00:00

Link: CVE-2020-6195

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2020-04-14T20:15:15.137

Modified: 2024-11-21T05:35:16.580

Link: CVE-2020-6195

cve-icon Redhat

No data.