CVE-2020-6181 is an HTTP Response Splitting vulnerability affecting SAP NetWeaver (various 702-740 versions) and SAP ABAP Platform (various 750-754 versions) due to invalidated data in SAML SSO HTTP response headers. With a CVSS score of 5.8 (Medium), this vulnerability can be exploited remotely with low complexity, potentially leading to information disclosure (integrity impact low) without requiring user interaction. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or inclusion in the KEV catalog. Community discussion and media coverage are minimal, with only one article from SecurityWeek mentioning it.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
7.50CPE matchmatch criteria | cpe:2.3:a:sap:abap_platform:7.50:*:*:*:*:*:*:* | ||
7.51CPE matchmatch criteria | cpe:2.3:a:sap:abap_platform:7.51:*:*:*:*:*:*:* | ||
7.52CPE matchmatch criteria | cpe:2.3:a:sap:abap_platform:7.52:*:*:*:*:*:*:* | ||
7.53CPE matchmatch criteria | cpe:2.3:a:sap:abap_platform:7.53:*:*:*:*:*:*:* | ||
7.54CPE matchmatch criteria | cpe:2.3:a:sap:abap_platform:7.54:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.