CVE-2020-6254
—CVSS 3.1
6.1 medium
EPSS
<1%p49
Published
()
Modified
Description
SAP Enterprise Threat Detection, versions 1.0, 2.0, does not sufficiently encode error response pages in case of errors, allowing XSS payload reflecting in the response, leading to reflected Cross Site Scripting.
- Vendors
- sap
- Products
- enterprise threat detection
- Weakness
- CWE-79
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
In the news0 stories
No ingested article mentions this CVE yet.