Vulnerability Description
SAP Enterprise Threat Detection, versions 1.0, 2.0, does not sufficiently encode error response pages in case of errors, allowing XSS payload reflecting in the response, leading to reflected Cross Site Scripting.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Sap | Enterprise Threat Detection | 1.0 |
Related Weaknesses (CWE)
References
- https://launchpad.support.sap.com/#/notes/2913293Permissions Required
- https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=545396222Vendor Advisory
- https://launchpad.support.sap.com/#/notes/2913293Permissions Required
- https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=545396222Vendor Advisory
FAQ
What is CVE-2020-6254?
CVE-2020-6254 is a vulnerability with a CVSS score of 6.1 (MEDIUM). SAP Enterprise Threat Detection, versions 1.0, 2.0, does not sufficiently encode error response pages in case of errors, allowing XSS payload reflecting in the response, leading to reflected Cross Sit...
How severe is CVE-2020-6254?
CVE-2020-6254 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-6254?
Check the references section above for vendor advisories and patch information. Affected products include: Sap Enterprise Threat Detection.