CVE-2020-6181
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
12/02/2020
Last modified:
21/02/2020
Description
Under some circumstances the SAML SSO implementation in the SAP NetWeaver (SAP_BASIS versions 702, 730, 731, 740 and SAP ABAP Platform (SAP_BASIS versions 750, 751, 752, 753, 754), allows an attacker to include invalidated data in the HTTP response header sent to a Web user, leading to HTTP Response Splitting vulnerability.
Impact
Base Score 3.x
5.80
Severity 3.x
MEDIUM
Base Score 2.0
5.00
Severity 2.0
MEDIUM
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:a:sap:abap_platform:7.50:*:*:*:*:*:*:* | ||
cpe:2.3:a:sap:abap_platform:7.51:*:*:*:*:*:*:* | ||
cpe:2.3:a:sap:abap_platform:7.52:*:*:*:*:*:*:* | ||
cpe:2.3:a:sap:abap_platform:7.53:*:*:*:*:*:*:* | ||
cpe:2.3:a:sap:abap_platform:7.54:*:*:*:*:*:*:* | ||
cpe:2.3:a:sap:netweaver:7.02:*:*:*:*:*:*:* | ||
cpe:2.3:a:sap:netweaver:7.30:*:*:*:*:*:*:* | ||
cpe:2.3:a:sap:netweaver:7.31:*:*:*:*:*:*:* | ||
cpe:2.3:a:sap:netweaver:7.40:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page