CVE-2020-6368

5.4MEDIUM

Key Information:

Vendor
SAP
Vendor
CVE Published:
15 October 2020

Summary

SAP Business Planning and Consolidation, versions - 750, 751, 752, 753, 754, 755, 810, 100, 200, can be abused by an attacker, allowing them to modify displayed application content without authorization, and to potentially obtain authentication information from other legitimate users, leading to Cross Site Scripting.

Affected Version(s)

SAP Business Planning and Consolidation < 750 < 750

SAP Business Planning and Consolidation < 751 < 751

SAP Business Planning and Consolidation < 752 < 752

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.