5.4
CVE-2020-6368
- EPSS 0.61%
- Veröffentlicht 15.10.2020 02:15:12
- Zuletzt bearbeitet 21.11.2024 05:35:35
- Erkennungen
SAP Business Planning and Consolidation, versions - 750, 751, 752, 753, 754, 755, 810, 100, 200, can be abused by an attacker, allowing them to modify displayed application content without authorization, and to potentially obtain authentication information from other legitimate users, leading to Cross Site Scripting.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
SAP ≫ Business Planning And Consolidation Version 100
SAP ≫ Business Planning And Consolidation Version 200
SAP ≫ Business Planning And Consolidation Version 750
SAP ≫ Business Planning And Consolidation Version 751
SAP ≫ Business Planning And Consolidation Version 752
SAP ≫ Business Planning And Consolidation Version 753
SAP ≫ Business Planning And Consolidation Version 754
SAP ≫ Business Planning And Consolidation Version 755
SAP ≫ Business Planning And Consolidation Version 810
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.61% | 0.45 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 5.4 | 2.3 | 2.7 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
|
| NIST | 3.5 | 6.8 | 2.9 |
AV:N/AC:M/Au:S/C:N/I:P/A:N
|
| SAP | 5.4 | 2.3 | 2.7 |
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
|
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=558632196
https://launchpad.support.sap.com/#/notes/2960825