SAP Marketing (Servlet), version-130,140,150, allows an authenticated attacker to invoke certain functions that are restricted. Limited knowledge of payload is required for an attacker to exploit the vulnerability and perform tasks related to contact and interaction data which impacts Confidentiality and Integrity of data in the application.
References
Link | Resource |
---|---|
https://launchpad.support.sap.com/#/notes/2961991 | Permissions Required |
https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=557449700 | Vendor Advisory |
https://launchpad.support.sap.com/#/notes/2961991 | Permissions Required |
https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=557449700 | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 05:35
Type | Values Removed | Values Added |
---|---|---|
References | () https://launchpad.support.sap.com/#/notes/2961991 - Permissions Required | |
References | () https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=557449700 - Vendor Advisory |
Information
Published : 2020-09-09 13:15
Updated : 2024-11-21 05:35
NVD link : CVE-2020-6320
Mitre link : CVE-2020-6320
CVE.ORG link : CVE-2020-6320
JSON object : View
Products Affected
sap
- marketing
CWE