Medium severity4.3NVD Advisory· Published Mar 10, 2020· Updated Jun 17, 2026
CVE-2020-6206
CVE-2020-6206
Description
SAP Cloud Platform Integration for Data Services, version 1.0, allows user inputs to be reflected as error or warning massages. This could mislead the victim to follow malicious instructions inserted by external attackers, leading to Cross Site Request Forgery.
Affected products
3- cpe:2.3:a:sap:cloud_platform_integration:1.0:*:*:*:*:data_services:*:*
- Range: = 1.0
- SAP SE/SAP Cloud Platform Integration for Data Servicesv5Range: < 1.0
Patches
Vulnerability mechanics
References
2- wiki.scn.sap.com/wiki/pages/viewpage.actionnvdVendor Advisory
- launchpad.support.sap.comnvdPermissions Required
News mentions
0No linked articles in our index yet.