SAP Enterprise Threat Detection, versions 1.0, 2.0, does not sufficiently encode error response pages in case of errors, allowing XSS payload reflecting in the response, leading to reflected Cross Site Scripting.
                
            References
                    | Link | Resource | 
|---|---|
| https://launchpad.support.sap.com/#/notes/2913293 | Permissions Required | 
| https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=545396222 | Vendor Advisory | 
Configurations
                    Configuration 1 (hide)
                                
                                
  | 
                        
Information
                Published : 2020-05-12 11:15
Updated : 2020-05-14 17:57
NVD link : CVE-2020-6254
Mitre link : CVE-2020-6254
JSON object : View
CWE
                
                    
                        
                        CWE-79
                        
            Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Products Affected
                sap
- enterprise_threat_detection
 


