CVE-2020-6181

Description

Under some circumstances the SAML SSO implementation in the SAP NetWeaver (SAP_BASIS versions 702, 730, 731, 740 and SAP ABAP Platform (SAP_BASIS versions 750, 751, 752, 753, 754), allows an attacker to include invalidated data in the HTTP response header sent to a Web user, leading to HTTP Response Splitting vulnerability.

Risk Information

Base Score
5.8
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N
EPSS Score
Exploitation Probability
0.305

Associated Vulnerability

VulnerabilityOS Platform
Multiple Vulnerabilities are affected in SAP NetWeaver and ABAP Platform (Service Data Collection) 7.02Windows
Multiple Vulnerabilities are affected in SAP NetWeaver and ABAP Platform (Service Data Collection) 7.40Windows
Vulnerabilities CVE-2020-6181,CVE-2020-6280,CVE-2020-6310 are affected in SAP ABAP Platform (ABAP Build Framework) 7.50Windows
Vulnerabilities CVE-2020-6181 are affected in SAP ABAP Platform (ABAP Build Framework) 7.51Windows
Vulnerabilities CVE-2020-6181 are affected in SAP ABAP Platform (ABAP Build Framework) 7.52Windows
Vulnerabilities CVE-2020-6181 are affected in SAP ABAP Platform (ABAP Build Framework) 7.53Windows
Vulnerabilities CVE-2020-6181 are affected in SAP ABAP Platform (ABAP Build Framework) 7.54Windows

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234