PT-2020-16518 · Sap · Sap Netweaver As Abap

Published

2020-12-09

·

Updated

2022-10-05

·

CVE-2020-26835

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions SAP NetWeaver AS ABAP versions 740 through 754
Description The issue arises from insufficient URL encoding, allowing an attacker to input malicious JavaScript in the URL. This could result in the execution of the malicious script in the browser, leading to a Reflected Cross-Site Scripting (XSS) issue.
Recommendations For SAP NetWeaver AS ABAP versions 740 through 754, update to a version that properly encodes URLs to prevent malicious JavaScript execution. As a temporary workaround, consider restricting user input in URLs to minimize the risk of exploitation.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2020-26835

Affected Products

Sap Netweaver As Abap