PT-2020-19098 · Sap · Sap Netweaver As Abap
Published
2020-09-09
·
Updated
2023-01-30
·
CVE-2020-6324
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
SAP Netweaver AS ABAP versions 700 through 755
Description
The issue allows an unauthenticated attacker to send a polluted URL to the victim. When the victim clicks on this URL, the attacker can read and modify the information available in the victim's browser, leading to Reflected Cross Site Scripting.
Recommendations
For versions 700 through 755, consider disabling the BSP Test Application sbspext table until a patch is available to prevent exploitation. Restrict access to the vulnerable application to minimize the risk of Reflected Cross Site Scripting attacks. Avoid using potentially polluted URLs in the affected application until the issue is resolved.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sap Netweaver As Abap