CVE-2020-6260
Last modified
CVE-2020-6260 is a medium-severity vulnerability rated 5.3/10 on the CVSS scale. SAP Solution Manager (Trace Analysis), version 7.20, allows an attacker to inject superflous data that can be displayed by the application, due to Incomplete XML Validation. The application shows additional data that do not actually exist.. EPSS estimates a 0.78% chance of exploitation in the next 30 days.
Description
SAP Solution Manager (Trace Analysis), version 7.20, allows an attacker to inject superflous data that can be displayed by the application, due to Incomplete XML Validation. The application shows additional data that do not actually exist.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Sap | Solution Manager | 7.20 |
References
- https://launchpad.support.sap.com/#/notes/2915126Permissions Required
- https://launchpad.support.sap.com/#/notes/2915126Permissions Required
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2020-6260?
How severe is CVE-2020-6260?
How do I fix CVE-2020-6260?
Are you affected by CVE-2020-6260?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
