SAP Enterprise Threat Detection, versions 1.0, 2.0, does not sufficiently encode error response pages in case of errors, allowing XSS payload reflecting in the response, leading to reflected Cross Site Scripting.
References
Link | Resource |
---|---|
https://launchpad.support.sap.com/#/notes/2913293 | Permissions Required |
https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=545396222 | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2020-05-12 18:15
Updated : 2024-02-28 17:47
NVD link : CVE-2020-6254
Mitre link : CVE-2020-6254
CVE.ORG link : CVE-2020-6254
JSON object : View
Products Affected
sap
- enterprise_threat_detection
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')