CVE-2020-6260: Medium severity sap netweaver solution manager vulnerability
SAP Solution Manager (Trace Analysis), version 7.20, allows an attacker to inject superflous data that can be displayed by the application, due to Incomplete XML Validation. The application shows additional data that do not actually exist.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this SAP Solution Manager vulnerability?
The vulnerability ID for this SAP Solution Manager vulnerability is CVE-2020-6260.
What is the severity rating of CVE-2020-6260?
The severity rating of CVE-2020-6260 is 5.3 (medium).
What is the affected software for CVE-2020-6260?
The affected software for CVE-2020-6260 is SAP Solution Manager version 7.20.
How does CVE-2020-6260 affect the application?
CVE-2020-6260 allows an attacker to inject superfluous data that can be displayed by the SAP Solution Manager application.
Is there any reference material available for CVE-2020-6260?
Yes, you can refer to the following links for more information: [1] https://launchpad.support.sap.com/#/notes/2915126 and [2] https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=547426775.