Vulnerability CVE-2020-6260


Published: 2020-06-10

Description:
SAP Solution Manager (Trace Analysis), version 7.20, allows an attacker to inject superflous data that can be displayed by the application, due to Incomplete XML Validation. The application shows additional data that do not actually exist.

Type:

CWE-91

(XML Injection (aka Blind XPath Injection))

CVSS2 => (AV:N/AC:L/Au:N/C:N/I:P/A:N)

CVSS Base Score
Impact Subscore
Exploitability Subscore
5/10
2.9/10
10/10
Exploit range
Attack complexity
Authentication
Remote
Low
No required
Confidentiality impact
Integrity impact
Availability impact
None
Partial
None
Affected software
SAP -> Solution manager 

 References:
https://launchpad.support.sap.com/#/notes/2915126
https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=547426775

Copyright 2020, cxsecurity.com

 

Back to Top