PT-2020-19055 · Sap · Sap Solution Manager

Published

2020-06-10

·

Updated

2020-06-16

·

CVE-2020-6260

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
Name of the Vulnerable Software and Affected Versions SAP Solution Manager (Trace Analysis) version 7.20
Description The issue allows an attacker to inject superfluous data that can be displayed by the application due to Incomplete XML Validation. This results in the application showing additional data that do not actually exist.
Recommendations For SAP Solution Manager (Trace Analysis) version 7.20, consider restricting the input validation to prevent superfluous data injection until a patch is available. As a temporary workaround, review and validate all XML data to ensure it conforms to expected formats and does not contain malicious input.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-6260

Affected Products

Sap Solution Manager