First published: Tue May 12 2020(Updated: )
SAP Enterprise Threat Detection, versions 1.0, 2.0, does not sufficiently encode error response pages in case of errors, allowing XSS payload reflecting in the response, leading to reflected Cross Site Scripting.
Credit: cna@sap.com
Affected Software | Affected Version | How to fix |
---|---|---|
SAP Enterprise Threat Detection | =1.0 | |
SAP Enterprise Threat Detection | =2.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-6254 has a high severity rating due to its potential to allow reflected Cross Site Scripting (XSS) attacks.
To fix CVE-2020-6254, update SAP Enterprise Threat Detection to the latest version where the issue has been addressed.
CVE-2020-6254 affects SAP Enterprise Threat Detection versions 1.0 and 2.0.
CVE-2020-6254 is a reflected Cross Site Scripting (XSS) vulnerability.
Yes, if exploited, CVE-2020-6254 can lead to unauthorized data exposure through malicious scripts.