CVE-2020-6206

MEDIUM

SAP Cloud Platform Integration - CSRF

Title source: llm
STIX 2.1

Description

SAP Cloud Platform Integration for Data Services, version 1.0, allows user inputs to be reflected as error or warning massages. This could mislead the victim to follow malicious instructions inserted by external attackers, leading to Cross Site Request Forgery.

References (2)

Core 2
Core References
Permissions Required x_refsource_misc
https://launchpad.support.sap.com/#/notes/2859004

Scores

CVSS v3 4.3
EPSS 0.0016
EPSS Percentile 37.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N

Details

CWE
CWE-352
Status published
Products (1)
sap/cloud_platform_integration 1.0
Published Mar 10, 2020
Tracked Since Feb 18, 2026