CVE-2020-6206
CVE-2020-6206
Vexday Risk Score
13Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 4.7EPSS 0.4%KEV nãoPoC —Nuclei —Metasploit —Patch —
Lifecycle
10 Mar 2020Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
SAP Cloud Platform Integration for Data Services, version 1.0, allows user inputs to be reflected as error or warning massages. This could mislead the victim to follow malicious instructions inserted by external attackers, leading to Cross Site Request Forgery.
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N
Affected products
SAP SE · SAP Cloud Platform Integration for Data ServicesWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →