PT-2020-3614 · Sap+8 · Sap Netweaver+9

Alejandro Cabrera Aldaya

+6

·

Published

2020-06-02

·

Updated

2024-12-12

·

CVE-2020-6829

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Firefox versions prior to 80 Firefox for Android versions prior to 80 SAP NetWeaver (affected versions not specified)
Description The issue is related to the use of the wNAF point multiplication algorithm during EC scalar point multiplication, which leaked partial information about the nonce used during signature generation. This allowed an attacker to compute the private key given an electro-magnetic trace of a few signature generations. Additionally, there is a vulnerability in the Knowledge Management component of the SAP NetWeaver platform related to the failure to neutralize script-related HTML tags on a web page, which could enable a remote attacker to perform cross-site scripting attacks.
Recommendations For Firefox versions prior to 80, update to version 80 or later. For Firefox for Android versions prior to 80, update to version 80 or later. For SAP NetWeaver, restrict access to the vulnerable Knowledge Management component to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for the SAP NetWeaver vulnerability.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2020-2482
ALT-PU-2020-2706
ALT-PU-2020-2932
ALT-PU-2020-3442
ALT-PU-2021-1367
ALT-PU-2021-3368
BDU:2020-03953
CESA-2020_4076
CESA-2021_0538
CVE-2020-6829
DLA-2388-1
DLA-3327-1
MGASA-2020-0318
OPENSUSE-SU-2024:10600-1
OPENSUSE-SU-2024:11058-1
OPENSUSE-SU-2024:14572-1
RHSA-2020:4076
RHSA-2020_4076
RHSA-2021:0538
RHSA-2021_0538
RLSA-2021:0538
SUSE-RU-2021:14818-1
SUSE-RU-2021:3115-1
SUSE-RU-2021:3115-2
SUSE-RU-2021:3116-1
USN-4455-1
USN-4474-1
USN-4474-2

Affected Products

Alt Linux
Astra Linux
Centos
Firefox
Firefox For Android
Linuxmint
Red Hat
Rocky Linux
Sap Netweaver
Ubuntu