PT-2020-19055 · Sap · Sap Solution Manager
Published
2020-06-10
·
Updated
2020-06-16
·
CVE-2020-6260
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
SAP Solution Manager (Trace Analysis) version 7.20
Description
The issue allows an attacker to inject superfluous data that can be displayed by the application due to Incomplete XML Validation. This results in the application showing additional data that do not actually exist.
Recommendations
For SAP Solution Manager (Trace Analysis) version 7.20, consider restricting the input validation to prevent superfluous data injection until a patch is available. As a temporary workaround, review and validate all XML data to ensure it conforms to expected formats and does not contain malicious input.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sap Solution Manager