Vulnerability Description
SAP NetWeaver (Knowledge Management), versions - 7.30, 7.31, 7.40, 7.50, allows the automatic execution of script content in a stored file due to inadequate filtering with the accessing user's privileges. If the accessing user has administrative privileges, then the execution of the script content could result in complete compromise of system confidentiality, integrity and availability, leading to Stored Cross Site Scripting.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Sap | Netweaver Knowledge Management | 7.30 |
Related Weaknesses (CWE)
References
- https://launchpad.support.sap.com/#/notes/2928635Permissions Required
- https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=552603345Vendor Advisory
- https://launchpad.support.sap.com/#/notes/2928635Permissions Required
- https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=552603345Vendor Advisory
FAQ
What is CVE-2020-6284?
CVE-2020-6284 is a vulnerability with a CVSS score of 9.0 (CRITICAL). SAP NetWeaver (Knowledge Management), versions - 7.30, 7.31, 7.40, 7.50, allows the automatic execution of script content in a stored file due to inadequate filtering with the accessing user's privile...
How severe is CVE-2020-6284?
CVE-2020-6284 has been rated CRITICAL with a CVSS base score of 9.0/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2020-6284?
Check the references section above for vendor advisories and patch information. Affected products include: Sap Netweaver Knowledge Management.