CVE-2020-26815

HIGH

SAP Fiori Launchpad News Tile Application 750-755 - Server-Side Request Forgery

Title source: llm
STIX 2.1

Description

SAP Fiori Launchpad (News tile Application), versions - 750,751,752,753,754,755, allows an unauthorized attacker to send a crafted request to a vulnerable web application. It is usually used to target internal systems behind firewalls that are normally inaccessible to an attacker from the external network to retrieve sensitive / confidential resources which are otherwise restricted for internal usage only, resulting in a Server-Side Request Forgery vulnerability.

References (2)

Core 2
Core References
Permissions Required x_refsource_misc
https://launchpad.support.sap.com/#/notes/2984627

Scores

CVSS v3 8.6
EPSS 0.0028
EPSS Percentile 51.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N

Details

CWE
CWE-918
Status published
Products (6)
sap/fiori_launchpad_\(news_tile_application\) 750
sap/fiori_launchpad_\(news_tile_application\) 751
sap/fiori_launchpad_\(news_tile_application\) 752
sap/fiori_launchpad_\(news_tile_application\) 753
sap/fiori_launchpad_\(news_tile_application\) 754
sap/fiori_launchpad_\(news_tile_application\) 755
Published Nov 10, 2020
Tracked Since Feb 18, 2026