PT-2020-19056 · Sap · Sap Solution Manager

Published

2020-07-01

·

Updated

2021-07-21

·

CVE-2020-6261

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions SAP Solution Manager (Trace Analysis) version 7.20
Description The issue allows an attacker to perform a log injection into the trace file due to incomplete XML validation, impairing the readability of the trace file.
Recommendations For SAP Solution Manager (Trace Analysis) version 7.20, ensure proper XML validation to prevent log injection attacks. As a temporary workaround, consider restricting access to the trace file until a patch is available.

Fix

Improper Encoding or Escaping of Output

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-6261

Affected Products

Sap Solution Manager