CVE-2020-6254 PUBLISHED CVSS 6.099999904632568 MEDIUM

SAP Enterprise Threat Detection, versions 1.0, 2.0, does not sufficiently encode error response pages in case of errors, allowing XSS payload reflecting in the response, leading to reflected Cross Site Scripting.

EPSS 0.19% · 40.8th percentile

Risk Scores

CVSS v3.0
6.099999904632568
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
EPSS Score
0.19%
40.8th percentile

Affected Products

VendorProductVersions
SAP SESAP Enterprise Threat Detection< 1.0, < 2.0
sapenterprise_threat_detection2.0, 1.0

Timeline

References

Open in Interactive Console →