Files
CVEs-PoC/2020/CVE-2020-6202.md
T
2024-05-25 21:48:12 +02:00

18 lines
856 B
Markdown

### [CVE-2020-6202](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-6202)
![](https://img.shields.io/static/v1?label=Product&message=SAP%20NetWeaver%20Application%20Server%20Java%20(User%20Management%20Engine)&color=blue)
![](https://img.shields.io/static/v1?label=Version&message=%3C7.10%20&color=brighgreen)
![](https://img.shields.io/static/v1?label=Vulnerability&message=Missing%20XML%20Validation&color=brighgreen)
### Description
SAP NetWeaver Application Server Java (User Management Engine), versions- 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50; does not sufficiently validate the LDAP data source configuration XML document accepted from an untrusted source, leading to Missing XML Validation.
### POC
#### Reference
- https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=540935305
#### Github
No PoCs found on GitHub currently.