← Vulnerability feed

Vulnerability record · CVE-2020-6308 · published 20 October 2020

CVE-2020-6308: SAP BusinessObjects BI Platform Web Services unauthenticated SSRF

Sap · Businessobjects Business Intelligence Platform

SAP BusinessObjects Business Intelligence Platform (Web Services) versions 410, 420 and 430 allow an unauthenticated attacker to inject arbitrary values as CMS parameters and trigger lookups against the internal network. Because the requests originate from the server, they reach internal services that are not externally accessible, turning the platform into an SSRF pivot.

5.3 CVSS 3.1 Medium EPSS 62% · top 0.9% CWE-918 · Server-side request forgery (SSRF)
5.3CVSS 3.1 base score, v2 5.0
62%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

SAP BusinessObjects Business Intelligence Platform (Web Services) versions - 410, 420, 430, allows an unauthenticated attacker to inject arbitrary values as CMS parameters to perform lookups on the internal network which is otherwise not accessible externally. On successful exploitation, attacker can scan internal network to determine internal infrastructure and gather information for further attacks like remote file inclusion, retrieve server files, bypass firewall and force the vulnerable server to perform malicious requests, resulting in a Server-Side Request Forgery vulnerability.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: medium.

high priorityUnauthenticated network-reachable SSRF with a very high EPSS score, though the CVSS impact is limited to low confidentiality and no KEV listing exists.

What it is

SAP BusinessObjects Business Intelligence Platform (Web Services) versions 410, 420 and 430 allow an unauthenticated attacker to inject arbitrary values as CMS parameters and trigger lookups against the internal network. Because the requests originate from the server, they reach internal services that are not externally accessible, turning the platform into an SSRF pivot.

Impact

An attacker can map internal infrastructure and gather information for follow-on attacks such as remote file inclusion, server file retrieval, firewall bypass, and forcing the server to issue malicious requests. The direct confidentiality impact is limited, but the internal reconnaissance value is significant.

Attack surface

Reachable over the network through the Web Services interface with no authentication and no user interaction, per the CVSS vector AV:N/AC:L/PR:N/UI:N. The attacker only needs to supply crafted CMS parameter values to the exposed service.

Exploitation

Not listed in CISA KEV and no public exploit or ransomware association is recorded in this entry, but EPSS is high at 0.617 (99th percentile), indicating elevated likelihood of exploitation activity. Reference tags are vendor advisory and permissions-required only, so no confirmed in-the-wild exploitation is documented here.

What to do

  • Apply the SAP security note 2943844 fix for the affected BusinessObjects BI Platform versions (410, 420, 430) as the first action.
  • Restrict outbound network access from the BI Web Services hosts so they cannot reach internal management, metadata, or file services.
  • Place the Web Services endpoints behind authentication and network access controls, and avoid exposing them directly to untrusted networks.
  • Validate and allowlist CMS parameter values where possible, rejecting arbitrary hostnames, URLs, and internal address ranges.
  • Monitor SAP advisories for updated guidance and confirm the deployed build includes the patch.

Detection

  • Monitor Web Services request logs for CMS parameters containing internal hostnames, IP addresses, or URL-like values.
  • Alert on outbound connections from BI Platform servers to internal ranges or unexpected ports that are not part of normal operation.
  • Correlate server-side requests to internal endpoints with the originating Web Services request to identify SSRF attempts.
  • Review DNS and proxy logs for lookups of internal-only names originating from the BI Platform hosts.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2020-6308 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2020-6242Sap businessobjects business intelligence platform missing authentication for critical function vulnerabilitySAP Business Objects Business Intelligence Platform (Live Data Connect), versions 1.0, 2.0, 2.1, 2.2, 2.3, allows an attacker to logon on the Central…EPSS 0.84%9.8CVE-2020-6195Sap businessobjects business intelligence platform cleartext transmission vulnerabilitySAP Business Objects Business Intelligence Platform (CMC), version 4.1, 4.2, shows cleartext password in the response, leading to Information Disclos…EPSS 0.63%9.6CVE-2020-26831Sap businessobjects business intelligence platform vulnerabilitySAP BusinessObjects BI Platform (Crystal Report), versions - 4.1, 4.2, 4.3, does not sufficiently validate uploaded XML entities during crystal repor…EPSS 1.1%9.3CVE-2024-28165Sap businessobjects business intelligence platform cross-site scripting vulnerabilitySAP Business Objects Business Intelligence Platform is vulnerable to stored XSS allowing an attacker to manipulate a parameter in the Opendocument UR…EPSS 0.57%9.1CVE-2025-0061Sap businessobjects business intelligence platform vulnerabilitySAP BusinessObjects Business Intelligence Platform allows an unauthenticated attacker to perform session hijacking over the network without any user …EPSS 0.51%9.1CVE-2023-24530Sap businessobjects business intelligence platform unrestricted file upload vulnerabilitySAP BusinessObjects Business Intelligence Platform (CMC) - versions 420, 430, allows an authenticated admin user to upload malicious code that can be…EPSS 0.56%9.1CVE-2020-6294Sap businessobjects business intelligence platform missing authentication for critical function vulnerabilityXvfb of SAP Business Objects Business Intelligence Platform, versions - 4.2, 4.3, platform on Unix does not perform any authentication checks for fun…EPSS 1.5%8.8CVE-2023-0022Sap businessobjects business intelligence platform code injection vulnerabilitySAP BusinessObjects Business Intelligence Analysis edition for OLAP allows an authenticated attacker to inject malicious code that can be executed by…EPSS 0.74%

Source: NIST National Vulnerability Database (record CVE-2020-6308), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.