CVE-2020-26815
8.6HIGH
Key Information:
- Vendor
- SAP
- Vendor
- CVE Published:
- 10 November 2020
Summary
SAP Fiori Launchpad (News tile Application), versions - 750,751,752,753,754,755, allows an unauthorized attacker to send a crafted request to a vulnerable web application. It is usually used to target internal systems behind firewalls that are normally inaccessible to an attacker from the external network to retrieve sensitive / confidential resources which are otherwise restricted for internal usage only, resulting in a Server-Side Request Forgery vulnerability.
Affected Version(s)
SAP Fiori Launchpad (News Tile Application) < 750 < 750
SAP Fiori Launchpad (News Tile Application) < 751 < 751
SAP Fiori Launchpad (News Tile Application) < 752 < 752
References
CVSS V3.1
Score:
8.6
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved