Learn about CVE-2020-6297, a medium severity vulnerability in SAP Data Intelligence < 3, allowing unauthorized access to confidential system configuration data. Find mitigation steps and best practices.
SAP Data Intelligence version < 3 allows attackers to access confidential system configuration information, leading to Information Disclosure.
Understanding CVE-2020-6297
Under certain conditions, the upgrade from SAP Data Hub 2.7 to SAP Data Intelligence version < 3 can result in a security vulnerability.
What is CVE-2020-6297?
CVE-2020-6297 is a vulnerability in SAP Data Intelligence that enables unauthorized access to restricted system configuration data, potentially leading to Information Disclosure.
The Impact of CVE-2020-6297
The vulnerability poses a medium severity risk with high impacts on confidentiality and integrity, allowing attackers to view sensitive system information.
Technical Details of CVE-2020-6297
SAP Data Intelligence version < 3 is susceptible to an Information Disclosure vulnerability.
Vulnerability Description
The upgrade process from SAP Data Hub 2.7 to SAP Data Intelligence version < 3 can be exploited by attackers to access confidential system configuration information.
Affected Systems and Versions
Exploitation Mechanism
Mitigation and Prevention
Steps to address and prevent the CVE-2020-6297 vulnerability.
Immediate Steps to Take
Long-Term Security Practices
Patching and Updates