Vulnerability Description
SAP Cloud Platform Integration for Data Services, version 1.0, allows user inputs to be reflected as error or warning massages. This could mislead the victim to follow malicious instructions inserted by external attackers, leading to Cross Site Request Forgery.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Sap | Cloud Platform Integration | 1.0 |
Related Weaknesses (CWE)
References
- https://launchpad.support.sap.com/#/notes/2859004Permissions Required
- https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=540935305Vendor Advisory
- https://launchpad.support.sap.com/#/notes/2859004Permissions Required
- https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=540935305Vendor Advisory
FAQ
What is CVE-2020-6206?
CVE-2020-6206 is a vulnerability with a CVSS score of 4.3 (MEDIUM). SAP Cloud Platform Integration for Data Services, version 1.0, allows user inputs to be reflected as error or warning massages. This could mislead the victim to follow malicious instructions inserted ...
How severe is CVE-2020-6206?
CVE-2020-6206 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-6206?
Check the references section above for vendor advisories and patch information. Affected products include: Sap Cloud Platform Integration.