PT-2020-19099 · Sap · Sap Netweaver

Published

2020-09-09

·

Updated

2020-09-14

·

CVE-2020-6326

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions SAP NetWeaver (Knowledge Management) versions 7.30 through 7.50
Description The issue allows an authenticated attacker to create malicious links in the UI. When clicked by a victim, these links will execute arbitrary Java scripts, thus extracting or modifying information otherwise restricted, leading to Stored Cross Site Scripting.
Recommendations For versions 7.30 through 7.50, update to a version that includes the fix for this issue to prevent Stored Cross Site Scripting attacks.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-6326

Affected Products

Sap Netweaver