CVE-2020-6205 Information

Description

SAP NetWeaver AS ABAP Business Server Pages (Smart Forms) SAP_BASIS versions- 7.00 7.01 7.02 7.10 7.11 7.30 7.31 7.40 7.50 7.51 7.52 7.53 7.54; does not sufficiently encode user controlled inputs allowing an unauthenticated attacker to non-permanently deface or modify displayed content and/or steal authentication information of the user and/or impersonate the user and access all information with the same rights as the target user leading to Reflected Cross Site Scripting Vulnerability.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Reference

https://launchpad.support.sap.com//notes/2884910 https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=540935305

Attack Complexity

LOW

Privileges Required

NONE

User Interaction Required

NONE

Scope

REQUIRED

Confidentiality Impact

CHANGED

Integrity Impact

LOW

Availability Impact

LOW

Base Score

NONE

Base Severity

6.1

Share on: