SAP Solution Manager (Trace Analysis), version 7.20, allows an attacker to inject superflous data that can be displayed by the application, due to Incomplete XML Validation. The application shows additional data that do not actually exist.
References
Link | Resource |
---|---|
https://launchpad.support.sap.com/#/notes/2915126 | Permissions Required |
https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=547426775 | Vendor Advisory |
Configurations
History
No history.
Information
Published : 2020-06-10 13:15
Updated : 2020-06-16 14:06
NVD link : CVE-2020-6260
Mitre link : CVE-2020-6260
CVE.ORG link : CVE-2020-6260
JSON object : View
Products Affected
sap
- solution_manager
CWE
CWE-91
XML Injection (aka Blind XPath Injection)