CVE-2020-26815: SSRF
SAP Fiori Launchpad (News tile Application), versions - 750,751,752,753,754,755, allows an unauthorized attacker to send a crafted request to a vulnerable web application. It is usually used to target internal systems behind firewalls that are normally inaccessible to an attacker from the external network to retrieve sensitive / confidential resources which are otherwise restricted for internal usage only, resulting in a Server-Side Request Forgery vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-26815?
CVE-2020-26815 has a medium severity rating, as it allows unauthorized attackers to send crafted requests to a vulnerable SAP Fiori Launchpad application.
How do I fix CVE-2020-26815?
To remediate CVE-2020-26815, users should apply the patches provided by SAP for impacted Fiori Launchpad versions.
Which SAP Fiori Launchpad versions are affected by CVE-2020-26815?
CVE-2020-26815 affects SAP Fiori Launchpad versions 750 through 755.
What type of attack does CVE-2020-26815 enable?
CVE-2020-26815 enables unauthorized attackers to target internal systems behind firewalls via crafted requests.
Who is at risk from CVE-2020-26815?
Organizations using vulnerable versions of SAP Fiori Launchpad are at risk from CVE-2020-26815 if proper security measures are not implemented.