CVE-2020-6284
Severity CVSS v4.0:
Pending analysis
Type:
CWE-79
Cross-Site Scripting (XSS)
Publication date:
12/08/2020
Last modified:
14/08/2020
Description
SAP NetWeaver (Knowledge Management), versions - 7.30, 7.31, 7.40, 7.50, allows the automatic execution of script content in a stored file due to inadequate filtering with the accessing user's privileges. If the accessing user has administrative privileges, then the execution of the script content could result in complete compromise of system confidentiality, integrity and availability, leading to Stored Cross Site Scripting.
Impact
Base Score 3.x
9.00
Severity 3.x
CRITICAL
Base Score 2.0
8.50
Severity 2.0
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:sap:netweaver_knowledge_management:7.30:*:*:*:*:*:*:* | ||
| cpe:2.3:a:sap:netweaver_knowledge_management:7.31:*:*:*:*:*:*:* | ||
| cpe:2.3:a:sap:netweaver_knowledge_management:7.40:*:*:*:*:*:*:* | ||
| cpe:2.3:a:sap:netweaver_knowledge_management:7.50:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



