S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Dec 16, 2023

CVE-2020-6308 Scanner

Detects 'Server-Side Request Forgery (SSRF)' vulnerability in SAP BusinessObjects Business Intelligence Platform (Web Services) affects v. 410, 420, 430.

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.7k
Times Used
continuous scan runs
4.7k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2020-6308
5.3
CVSSmedium
Exploitable remotely over the internet · no authentication required.

SAP BusinessObjects Business Intelligence Platform (Web Services) versions - 410, 420, 430, allows an unauthenticated attacker to inject arbitrary values as CMS parameters to perform lookups on the internal network which is otherwise not accessible externally. On successful exploitation, attacker can scan internal network to determine internal infrastructure and gather information for further attacks like remote file inclusion, retrieve server files, bypass firewall and force the vulnerable server to perform malicious requests, resulting in a Server-Side Request Forgery vulnerability.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
SAP BusinessObjects Business Intelligence Platform (Web Services)by SAP SE
< 410
Updated Aug 21, 2026View on NVD →
Detail

SAP BusinessObjects Business Intelligence Platform (Web Services) is a widely-used software platform for data analysis and reporting. It allows businesses to gather data from multiple sources in real-time to generate reports, charts, and visualizations that help them make informed decisions.

However, despite its popularity, the software has been found to have a critical vulnerability that could potentially put millions of users at risk. The vulnerability, known as CVE-2020-6308, allows an unauthenticated attacker to inject arbitrary values as CMS parameters in order to perform network lookups that are not accessible from outside the organization.

When exploited, this vulnerability can allow the attacker to scan an internal network to gather sensitive information that can be used to launch further attacks such as remote file inclusion, retrieving server files, bypassing firewalls, and forcing vulnerable servers to perform malicious requests. This opens up the possibility of a Server-Side Request Forgery (SSRF) vulnerability, which can be particularly devastating for businesses.

At s4e.io, we offer highly advanced vulnerability scanning and management services that can help detect and mitigate these types of vulnerabilities before they can be exploited. With our cutting-edge technology and experienced cybersecurity professionals, you can rest assured that your digital assets are always protected. So, take advantage of our pro features and keep your business secure!

 

REFERENCES

Solution Advice

Protecting your organization against this vulnerability is crucial to ensuring the safety and security of your digital assets. There are several steps that can be taken to minimize the risk of exploitation, including:

  • Keeping your SAP BusinessObjects Business Intelligence Platform up-to-date with the latest patches and security updates.
  • Implementing strict access controls to limit access to the platform to authorized users only.
  • Regularly performing security audits and vulnerability assessments to detect and resolve potential issues.
  • Education and awareness – ensuring all staff are aware of cybersecurity threats and the measures they can take to protect themselves and the business.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2020-6308 scanner - Server-Side Request Forgery (SSRF) vulnerability in SAP BusinessObjects Business Intelligence Platform (Web Services) | S4E