CVE-2020-6284 Information
Feb 14, 2021
cve
Description
SAP NetWeaver (Knowledge Management) versions - 7.30 7.31 7.40 7.50 allows the automatic execution of script content in a stored file due to inadequate filtering with the accessing user’s privileges. If the accessing user has administrative privileges then the execution of the script content could result in complete compromise of system confidentiality integrity and availability leading to Stored Cross Site Scripting.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
Reference
https://launchpad.support.sap.com//notes/2928635 https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=552603345
Attack Complexity
LOW
Privileges Required
LOW
User Interaction Required
LOW
Scope
REQUIRED
Confidentiality Impact
CHANGED
Integrity Impact
HIGH
Availability Impact
HIGH
Base Score
HIGH
Base Severity
9.0
Share on: