SAP Solution Manager (Trace Analysis), version 7.20, allows an attacker to inject superflous data that can be displayed by the application, due to Incomplete XML Validation. The application shows additional data that do not actually exist.
References
Link | Resource |
---|---|
https://launchpad.support.sap.com/#/notes/2915126 | Permissions Required |
https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=547426775 | Vendor Advisory |
https://launchpad.support.sap.com/#/notes/2915126 | Permissions Required |
https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=547426775 | Vendor Advisory |
Configurations
History
21 Nov 2024, 05:35
Type | Values Removed | Values Added |
---|---|---|
References | () https://launchpad.support.sap.com/#/notes/2915126 - Permissions Required | |
References | () https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=547426775 - Vendor Advisory |
Information
Published : 2020-06-10 13:15
Updated : 2024-11-21 05:35
NVD link : CVE-2020-6260
Mitre link : CVE-2020-6260
CVE.ORG link : CVE-2020-6260
JSON object : View
Products Affected
sap
- solution_manager
CWE
CWE-91
XML Injection (aka Blind XPath Injection)