First published: Thu Oct 15 2020(Updated: )
SAP Business Planning and Consolidation, versions - 750, 751, 752, 753, 754, 755, 810, 100, 200, can be abused by an attacker, allowing them to modify displayed application content without authorization, and to potentially obtain authentication information from other legitimate users, leading to Cross Site Scripting.
Credit: cna@sap.com
Affected Software | Affected Version | How to fix |
---|---|---|
Sap Business Planning And Consolidation | =100 | |
Sap Business Planning And Consolidation | =200 | |
Sap Business Planning And Consolidation | =750 | |
Sap Business Planning And Consolidation | =751 | |
Sap Business Planning And Consolidation | =752 | |
Sap Business Planning And Consolidation | =753 | |
Sap Business Planning And Consolidation | =754 | |
Sap Business Planning And Consolidation | =755 | |
Sap Business Planning And Consolidation | =810 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-6368 has a critical severity level as it allows unauthorized content modification and potential access to authentication information.
To fix CVE-2020-6368, apply the latest security patches provided by SAP for the affected versions of Business Planning and Consolidation.
CVE-2020-6368 affects versions 750, 751, 752, 753, 754, 755, 810, 100, and 200 of SAP Business Planning and Consolidation.
CVE-2020-6368 can facilitate attacks that permit the alteration of displayed content and may expose authentication credentials of legitimate users.
Currently, official workarounds for CVE-2020-6368 have not been provided, and it is recommended to apply patches as soon as possible.