PT-2020-19094 · Sap · Sap Marketing
Published
2020-09-09
·
Updated
2021-07-21
·
CVE-2020-6320
CVSS v3.1
9.6
Critical
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
SAP Marketing (Servlet) versions 130 through 150
Description
The issue allows an authenticated attacker to invoke certain restricted functions, potentially impacting the Confidentiality and Integrity of data related to contact and interaction. An attacker with limited knowledge of the payload can exploit this to perform specific tasks.
Recommendations
For versions 130 through 150, consider restricting access to the affected functions until a fix is available. As a temporary workaround, limit the invocation of restricted functions to authorized personnel only.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Sap Marketing