PT-2020-16500 · Sap · Sap Fiori Launchpad
Published
2020-11-10
·
Updated
2020-11-24
·
CVE-2020-26815
CVSS v3.1
8.6
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
SAP Fiori Launchpad (News tile Application) versions 750,751,752,753,754,755
Description
The issue allows an unauthorized attacker to send a crafted request to a vulnerable web application, typically used to target internal systems behind firewalls that are normally inaccessible from the external network. This results in the retrieval of sensitive or confidential resources that are otherwise restricted for internal usage only, leading to a Server-Side Request Forgery vulnerability.
Recommendations
For versions 750,751,752,753,754,755, consider restricting access to the vulnerable web application to minimize the risk of exploitation.
As a temporary workaround, consider disabling the News tile Application until a patch is available.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sap Fiori Launchpad