Medium severity6.1NVD Advisory· Published May 12, 2020· Updated Jun 17, 2026
CVE-2020-6254
CVE-2020-6254
Description
SAP Enterprise Threat Detection, versions 1.0, 2.0, does not sufficiently encode error response pages in case of errors, allowing XSS payload reflecting in the response, leading to reflected Cross Site Scripting.
Affected products
4- SAP SE/SAP Enterprise Threat Detectionv5Range: < 1.0
1.0, 2.0+ 2 more
- (no CPE)range: 1.0, 2.0
- cpe:2.3:a:sap:enterprise_threat_detection:1.0:*:*:*:*:*:*:*
- cpe:2.3:a:sap:enterprise_threat_detection:2.0:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
2- wiki.scn.sap.com/wiki/pages/viewpage.actionnvdVendor Advisory
- launchpad.support.sap.comnvdPermissions Required
News mentions
0No linked articles in our index yet.