CVE-2020-6293 Information

Description

SAP NetWeaver (Knowledge Management) versions - 7.30 7.31 7.40 7.50 allows an unauthenticated attacker to upload a malicious file and also to access modify or make unavailable existing files but the impact is limited to the files themselves and is restricted by other policies such as access control lists and other upload file size restrictions leading to Unrestricted File Upload.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N

Reference

https://launchpad.support.sap.com//notes/2938162 https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=552603345

Attack Complexity

LOW

Privileges Required

NONE

User Interaction Required

NONE

Scope

NONE

Confidentiality Impact

UNCHANGED

Integrity Impact

LOW

Availability Impact

LOW

Base Score

NONE

Base Severity

6.5

Share on: