cbcvebase.
CVE-2020-6303
published 2020-01-14

CVE-2020-6303: SAP Disclosure Management, before version 10.1, does not validate user input properly in specific use cases leading to Cross-Site Scripting.

medium5.4CVSS 3.1
AVNACLPRLUIRSCCLILAN
SAP Disclosure Management, before version 10.1, does not validate user input properly in specific use cases leading to Cross-Site Scripting.

Affected

2 ranges
VendorProductVersion rangeFixed in
sapdisclosure_management< 10.110.1
sap_sesap_disclosure_management< 10.110.1