CVE-2020-6187
MEDIUMSAP NetWeaver Guided Procedures 7.10-7.50 - XML External Entity Injection
Title source: llmDescription
SAP NetWeaver (Guided Procedures), versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, does not sufficiently validate an XML document input from a compromised admin, leading to Denial of Service.
References (2)
Core 2
Core References
Vendor Advisory x_refsource_misc
https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=537788812
Permissions Required, Vendor Advisory x_refsource_misc
https://launchpad.support.sap.com/#/notes/2864415
Scores
CVSS v3
4.9
EPSS
0.0029
EPSS Percentile
52.9%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
Details
CWE
CWE-611
Status
published
Products (7)
sap/netweaver_guided_procedures
7.10
sap/netweaver_guided_procedures
7.11
sap/netweaver_guided_procedures
7.20
sap/netweaver_guided_procedures
7.30
sap/netweaver_guided_procedures
7.31
sap/netweaver_guided_procedures
7.40
sap/netweaver_guided_procedures
7.50
Published
Feb 12, 2020
Tracked Since
Feb 18, 2026