CVE-2020-6368
CVE-2020-6368
Vexday Risk Score
13Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 5.4EPSS 0.6%KEV nãoPoC —Nuclei —Metasploit —Patch —
Lifecycle
15 Oct 2020Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
SAP Business Planning and Consolidation, versions - 750, 751, 752, 753, 754, 755, 810, 100, 200, can be abused by an attacker, allowing them to modify displayed application content without authorization, and to potentially obtain authentication information from other legitimate users, leading to Cross Site Scripting.
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Affected products
SAP SE · SAP Business Planning and ConsolidationWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →