CVE-2020-26825
Summary
| CVE | CVE-2020-26825 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-11-13 15:15:00 UTC |
| Updated | 2020-11-24 21:12:00 UTC |
| Description | SAP Fiori Launchpad (News tile Application), versions - 750,751,752,753,754,755, allows an unauthorized attacker to use SAP Fiori Launchpad News tile Application to send malicious code, to a different end user (victim), because News tile does not sufficiently encode user controlled inputs, resulting in Reflected Cross-Site Scripting (XSS) vulnerability. Information maintained in the victim's web browser can be read, modified, and sent to the attacker. The malicious code cannot significantly impact the victim's browser and the victim can easily close the browser tab to terminate it. |
Risk And Classification
Problem Types: CWE-79
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Sap | Fiori Launchpad News Tile Application | 750 | All | All | All |
| Application | Sap | Fiori Launchpad News Tile Application | 751 | All | All | All |
| Application | Sap | Fiori Launchpad News Tile Application | 752 | All | All | All |
| Application | Sap | Fiori Launchpad News Tile Application | 753 | All | All | All |
| Application | Sap | Fiori Launchpad News Tile Application | 754 | All | All | All |
| Application | Sap | Fiori Launchpad News Tile Application | 755 | All | All | All |
| Application | Sap | Fiori Launchpad News Tile Application | 750 | All | All | All |
| Application | Sap | Fiori Launchpad News Tile Application | 751 | All | All | All |
| Application | Sap | Fiori Launchpad News Tile Application | 752 | All | All | All |
| Application | Sap | Fiori Launchpad News Tile Application | 753 | All | All | All |
| Application | Sap | Fiori Launchpad News Tile Application | 754 | All | All | All |
| Application | Sap | Fiori Launchpad News Tile Application | 755 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| SAP Security Patch Day – November 2020 - Product Security Response at SAP - Community Wiki | MISC | wiki.scn.sap.com | Vendor Advisory |
| launchpad.support.sap.com | MISC | launchpad.support.sap.com | Permissions Required |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.