Server-Side Request Forgery (SSRF) in SAP BusinessObjects Business Intelligence suite - CVE-2020-6308
Published: October 20, 2020 / Updated: August 16, 2024
Vulnerability details
The disclosed vulnerability allows a remote attacker to perform SSRF attacks.
The vulnerability exists due to insufficient validation of user-supplied input. A remote attacker can send a specially crafted HTTP request and trick the application to initiate requests to arbitrary systems.
Successful exploitation of this vulnerability may allow a remote attacker gain access to sensitive data, located in the local network or send malicious requests to other servers from the vulnerable system.
Affected software
How to mitigate CVE-2020-6308
Links to Public Exploits and PoC-codes
- Exploit #10398 - sap_bo_launchpad-ssrf-timing_attack (This script exploits and performs an SSRF (Server-Side Request Forgery) and Timing Attack against the SAP BusinessObjects Launchpad (CVE-2020-6308). It attempts to determine the status of various ports on a target IP a (August 16, 2024)
- Exploit #6656 - CVE-2020-6308 (Exploit script for SAP Business Objects SSRF) (August 25, 2021)
- Exploit #5134 - CVE-2020-6308-mass-exploiter (CVE-2020-6308 mass exploiter/fuzzer.) (February 9, 2021)
- Exploit #4973 - CVE-2020-6308-PoC (PoC CVE-2020-6308) (December 28, 2020)
- Exploit #4970 - CVE-2020-6308 (PoC CVE-2020-6308) (December 28, 2020)
- Exploit #4877 - CVE-2020-6308-mass-exploiter (CVE-2020-6308 mass exploiter/fuzzer.) (November 26, 2020)