HIGH
SAP Marketing (Servlet), version-130,140,150, allows an authenticated attacker to invoke certain functions that are restricted
Published Sep 9, 2020
8.1
HIGHCVSS 3.1
EPSS 0.95%
Description
SAP Marketing (Servlet), version-130,140,150, allows an authenticated attacker to invoke certain functions that are restricted. Limited knowledge of payload is required for an attacker to exploit the vulnerability and perform tasks related to contact and interaction data which impacts Confidentiality and Integrity of data in the application.
Affected products
-
- Version < 130StatusaffectedConstraints-
- Version < 140StatusaffectedConstraints-
- Version < 150StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| SAP SE | SAP Marketing (Mobile Channel Servlet) | n/a |
|
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (0)
No CWE recorded.
References (3)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2020-27470 Advisory
- https://launchpad.support.sap.com/#/notes/2961991 x_refsource_MISCPermissions Required
- https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=557449700 x_refsource_MISCVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2020-27470 | Advisory | |
| https://launchpad.support.sap.com/#/notes/2961991 | x_refsource_MISCPermissions Required | |
| https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=557449700 | x_refsource_MISCVendor Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner sap
Published Sep 9, 2020
Updated Aug 4, 2024
Reserved Jan 8, 2020
Link CVE-2020-6320
CISA Vulnrichment
Updated n/a
ENISA EUVD
EUVD-2020-27470 Assigner sap
Published Sep 9, 2020
Updated Aug 4, 2024
Exploited since n/a
Link EUVD-2020-27470