CVE-2020-6206

Severity CVSS v4.0:
Pending analysis
Type:
CWE-352 Cross-Site Request Forgery (CSRF)
Publication date:
10/03/2020
Last modified:
12/03/2020

Description

SAP Cloud Platform Integration for Data Services, version 1.0, allows user inputs to be reflected as error or warning massages. This could mislead the victim to follow malicious instructions inserted by external attackers, leading to Cross Site Request Forgery.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:sap:cloud_platform_integration:1.0:*:*:*:*:data_services:*:*