Cross-Site Scripting in SAP Disclosure Management Before Version 10.1
CVE-2020-6303
5.4MEDIUM
Summary
SAP Disclosure Management, prior to version 10.1, is vulnerable to Cross-Site Scripting (XSS) due to insufficient validation of user input in certain scenarios. This flaw could allow attackers to inject malicious scripts into web pages viewed by other users, potentially leading to unauthorized actions or data theft. Organizations using affected versions should consider applying the latest updates to mitigate the risks associated with this vulnerability.
Affected Version(s)
SAP Disclosure Management < 10.1
References
CVSS V3.1
Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved