CVE-2020-6367 Information
Feb 14, 2021
cve
Description
There is a reflected cross site scripting vulnerability in SAP NetWeaver Composite Application Framework versions - 7.20 7.30 7.31 7.40 7.50. An unauthenticated attacker can trick an unsuspecting authenticated user to click on a malicious link. The end users browser has no way to know that the script should not be trusted and will execute the script resulting in sensitive information being disclosed or modified.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Reference
https://launchpad.support.sap.com//notes/2972661 https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=558632196
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
REQUIRED
Confidentiality Impact
CHANGED
Integrity Impact
LOW
Availability Impact
LOW
Base Score
NONE
Base Severity
6.1
Share on: