CVE-2020-6205
Severity CVSS v4.0:
Pending analysis
Type:
CWE-79
Cross-Site Scripting (XSS)
Publication date:
10/03/2020
Last modified:
26/09/2023
Description
SAP NetWeaver AS ABAP Business Server Pages (Smart Forms), SAP_BASIS versions- 7.00, 7.01, 7.02, 7.10, 7.11, 7.30, 7.31, 7.40, 7.50, 7.51, 7.52, 7.53, 7.54; does not sufficiently encode user controlled inputs, allowing an unauthenticated attacker to non-permanently deface or modify displayed content and/or steal authentication information of the user and/or impersonate the user and access all information with the same rights as the target user, leading to Reflected Cross Site Scripting Vulnerability.
Impact
Base Score 3.x
6.10
Severity 3.x
MEDIUM
Base Score 2.0
4.30
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:sap:netweaver_as_abap_business_server_pages:7.00:*:*:*:*:*:*:* | ||
| cpe:2.3:a:sap:netweaver_as_abap_business_server_pages:7.01:*:*:*:*:*:*:* | ||
| cpe:2.3:a:sap:netweaver_as_abap_business_server_pages:7.02:*:*:*:*:*:*:* | ||
| cpe:2.3:a:sap:netweaver_as_abap_business_server_pages:7.10:*:*:*:*:*:*:* | ||
| cpe:2.3:a:sap:netweaver_as_abap_business_server_pages:7.11:*:*:*:*:*:*:* | ||
| cpe:2.3:a:sap:netweaver_as_abap_business_server_pages:7.30:*:*:*:*:*:*:* | ||
| cpe:2.3:a:sap:netweaver_as_abap_business_server_pages:7.31:*:*:*:*:*:*:* | ||
| cpe:2.3:a:sap:netweaver_as_abap_business_server_pages:7.40:*:*:*:*:*:*:* | ||
| cpe:2.3:a:sap:netweaver_as_abap_business_server_pages:7.50:*:*:*:*:*:*:* | ||
| cpe:2.3:a:sap:netweaver_as_abap_business_server_pages:7.51:*:*:*:*:*:*:* | ||
| cpe:2.3:a:sap:netweaver_as_abap_business_server_pages:7.52:*:*:*:*:*:*:* | ||
| cpe:2.3:a:sap:netweaver_as_abap_business_server_pages:7.53:*:*:*:*:*:*:* | ||
| cpe:2.3:a:sap:netweaver_as_abap_business_server_pages:7.54:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



