← Back

CVE-2020-6181

nvd nist
Published: Feb 12, 2020Modified: Nov 21, 2024

JSON object

Loading...
5.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N
Exploitability: 3.9 / Impact: 1.4
Source: NVD

Description

Under some circumstances the SAML SSO implementation in the SAP NetWeaver (SAP_BASIS versions 702, 730, 731, 740 and SAP ABAP Platform (SAP_BASIS versions 750, 751, 752, 753, 754), allows an attacker to include invalidated data in the HTTP response header sent to a Web user, leading to HTTP Response Splitting vulnerability.

Affected (9)

2 products
Abap Platform
Netweaver
Configuration A
9 vulnerable
Vulnerable SoftwareAffected Versions
Sap
Version 7.50
Version 7.51
Version 7.52
Version 7.53
Version 7.54
Sap
Version 7.02
Version 7.30
Version 7.31
Version 7.40

References (4)

Source: cna@sap.com
Permissions RequiredVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Permissions RequiredVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.