CVE-2020-6320

HIGH

SAP Marketing (Servlet) - Auth Bypass

Title source: llm
STIX 2.1

Description

SAP Marketing (Servlet), version-130,140,150, allows an authenticated attacker to invoke certain functions that are restricted. Limited knowledge of payload is required for an attacker to exploit the vulnerability and perform tasks related to contact and interaction data which impacts Confidentiality and Integrity of data in the application.

References (2)

Core 2
Core References
Permissions Required x_refsource_misc
https://launchpad.support.sap.com/#/notes/2961991

Scores

CVSS v3 8.1
EPSS 0.0036
EPSS Percentile 58.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

Details

Status published
Products (3)
sap/marketing 130
sap/marketing 140
sap/marketing 150
Published Sep 09, 2020
Tracked Since Feb 18, 2026