CVE-2020-6181

5.8MEDIUM

Key Information:

Vendor
SAP
Vendor
CVE Published:
12 February 2020

Summary

Under some circumstances the SAML SSO implementation in the SAP NetWeaver (SAP_BASIS versions 702, 730, 731, 740 and SAP ABAP Platform (SAP_BASIS versions 750, 751, 752, 753, 754), allows an attacker to include invalidated data in the HTTP response header sent to a Web user, leading to HTTP Response Splitting vulnerability.

Affected Version(s)

SAP ABAP Platform (SAP Basis) = 7.50 = 7.50

SAP ABAP Platform (SAP Basis) = 7.51 = 7.51

SAP ABAP Platform (SAP Basis) = 7.52 = 7.52

References

CVSS V3.1

Score:
5.8
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.