CVE-2020-6181

MEDIUM

SAP NetWeaver <753 - HTTP Response Splitting

Title source: llm
STIX 2.1

Description

Under some circumstances the SAML SSO implementation in the SAP NetWeaver (SAP_BASIS versions 702, 730, 731, 740 and SAP ABAP Platform (SAP_BASIS versions 750, 751, 752, 753, 754), allows an attacker to include invalidated data in the HTTP response header sent to a Web user, leading to HTTP Response Splitting vulnerability.

References (2)

Core 2
Core References
Permissions Required, Vendor Advisory x_refsource_misc
https://launchpad.support.sap.com/#/notes/2880744

Scores

CVSS v3 5.8
EPSS 0.0031
EPSS Percentile 53.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N

Details

Status published
Products (9)
sap/abap_platform 7.50
sap/abap_platform 7.51
sap/abap_platform 7.52
sap/abap_platform 7.53
sap/abap_platform 7.54
sap/netweaver 7.02
sap/netweaver 7.30
sap/netweaver 7.31
sap/netweaver 7.40
Published Feb 12, 2020
Tracked Since Feb 18, 2026