CVE Vulnerabilities

CVE-2020-6181

Published: Feb 12, 2020 | Modified: Nov 21, 2024
CVSS 3.x
5.8
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Under some circumstances the SAML SSO implementation in the SAP NetWeaver (SAP_BASIS versions 702, 730, 731, 740 and SAP ABAP Platform (SAP_BASIS versions 750, 751, 752, 753, 754), allows an attacker to include invalidated data in the HTTP response header sent to a Web user, leading to HTTP Response Splitting vulnerability.

Affected Software

NameVendorStart VersionEnd Version
Abap_platformSap7.50 (including)7.50 (including)
Abap_platformSap7.51 (including)7.51 (including)
Abap_platformSap7.52 (including)7.52 (including)
Abap_platformSap7.53 (including)7.53 (including)
Abap_platformSap7.54 (including)7.54 (including)
NetweaverSap7.02 (including)7.02 (including)
NetweaverSap7.30 (including)7.30 (including)
NetweaverSap7.31 (including)7.31 (including)
NetweaverSap7.40 (including)7.40 (including)

References