CVE-2020-6320
CVE-2020-6320
Vexday Risk Score
28Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 9.6EPSS 1.0%KEV nãoPoC —Nuclei —Metasploit —Patch —
Lifecycle
09 Sep 2020Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
SAP Marketing (Servlet), version-130,140,150, allows an authenticated attacker to invoke certain functions that are restricted. Limited knowledge of payload is required for an attacker to exploit the vulnerability and perform tasks related to contact and interaction data which impacts Confidentiality and Integrity of data in the application.
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N
Affected products
SAP SE · SAP Marketing (Mobile Channel Servlet)Want to know if your infrastructure is exposed to this?
Talk to TrueHacking →