CVE-2020-6260 Vulnerability Details

  /     /     /  

CVE-2020-6260 Metadata Quick Info

CVE Published: 10/06/2020 | CVE Updated: 04/08/2024 | CVE Year: 2020
Source: sap | Vendor: SAP SE | Product: SAP Solution Manager (Trace Analysis)
Status : PUBLISHED

CVE-2020-6260 Description

SAP Solution Manager (Trace Analysis), version 7.20, allows an attacker to inject superflous data that can be displayed by the application, due to Incomplete XML Validation. The application shows additional data that do not actually exist.

Metrics

CVSS Version: 3.1 | Base Score: n/a
Vector: n/a

l➤ Exploitability Metrics:
    Attack Vector (AV)*
    Attack Complexity (AC)*
    Privileges Required (PR)*
    User Interaction (UI)*
    Scope (S)*

l➤ Impact Metrics:
    Confidentiality Impact (C)*
    Integrity Impact (I)*
    Availability Impact (A)*

Weakness Enumeration (CWE)

CWE-ID:
CWE Name: Incomplete XML Validation
Source: SAP SE

Common Attack Pattern Enumeration and Classification (CAPEC)

CAPEC-ID:
CAPEC Description:


Source: NVD (National Vulnerability Database).