Description
SAP Marketing (Servlet), version-130,140,150, allows an authenticated attacker to invoke certain functions that are restricted. Limited knowledge of payload is required for an attacker to exploit the vulnerability and perform tasks related to contact and interaction data which impacts Confidentiality and Integrity of data in the application.
References (2)
Core 2
Core References
Vendor Advisory x_refsource_misc
https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=557449700
Permissions Required x_refsource_misc
https://launchpad.support.sap.com/#/notes/2961991
Scores
CVSS v3
8.1
EPSS
0.0036
EPSS Percentile
58.6%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Details
Status
published
Products (3)
sap/marketing
130
sap/marketing
140
sap/marketing
150
Published
Sep 09, 2020
Tracked Since
Feb 18, 2026