5.4
CVE-2020-6272
- EPSS 0.54%
- Veröffentlicht 15.10.2020 02:15:12
- Zuletzt bearbeitet 21.11.2024 05:35:25
- Erkennungen
SAP Commerce Cloud versions - 1808, 1811, 1905, 2005, does not sufficiently encode user inputs, which allows an authenticated and authorized content manager to inject malicious script into several web CMS components. These can be saved and later triggered, if an affected web page is visited, resulting in Cross-Site Scripting (XSS) vulnerability.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
SAP ≫ Commerce Cloud Version 1808
SAP ≫ Commerce Cloud Version 1811
SAP ≫ Commerce Cloud Version 1905
SAP ≫ Commerce Cloud Version 2005
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.54% | 0.414 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 5.4 | 2.3 | 2.7 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
|
| NIST | 3.5 | 6.8 | 2.9 |
AV:N/AC:M/Au:S/C:N/I:P/A:N
|
| SAP | 5.4 | 2.3 | 2.7 |
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
|
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
https://launchpad.support.sap.com/#/notes/2917381
https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=558632196