PT-2020-19098 · Sap · Sap Netweaver As Abap

Published

2020-09-09

·

Updated

2023-01-30

·

CVE-2020-6324

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions SAP Netweaver AS ABAP versions 700 through 755
Description The issue allows an unauthenticated attacker to send a polluted URL to the victim. When the victim clicks on this URL, the attacker can read and modify the information available in the victim's browser, leading to Reflected Cross Site Scripting.
Recommendations For versions 700 through 755, consider disabling the BSP Test Application sbspext table until a patch is available to prevent exploitation. Restrict access to the vulnerable application to minimize the risk of Reflected Cross Site Scripting attacks. Avoid using potentially polluted URLs in the affected application until the issue is resolved.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2020-6324

Affected Products

Sap Netweaver As Abap