Vulnerability Description
SAP NetWeaver (Knowledge Management), versions - 7.30, 7.31, 7.40, 7.50, allows an unauthenticated attacker to upload a malicious file and also to access, modify or make unavailable existing files but the impact is limited to the files themselves and is restricted by other policies such as access control lists and other upload file size restrictions, leading to Unrestricted File Upload.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Sap | Netweaver Knowledge Management | 7.30 |
Related Weaknesses (CWE)
References
- https://launchpad.support.sap.com/#/notes/2938162Permissions Required
- https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=552603345Vendor Advisory
- https://launchpad.support.sap.com/#/notes/2938162Permissions Required
- https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=552603345Vendor Advisory
FAQ
What is CVE-2020-6293?
CVE-2020-6293 is a vulnerability with a CVSS score of 6.5 (MEDIUM). SAP NetWeaver (Knowledge Management), versions - 7.30, 7.31, 7.40, 7.50, allows an unauthenticated attacker to upload a malicious file and also to access, modify or make unavailable existing files but...
How severe is CVE-2020-6293?
CVE-2020-6293 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-6293?
Check the references section above for vendor advisories and patch information. Affected products include: Sap Netweaver Knowledge Management.