CVE-2020-6313
Summary
| CVE | CVE-2020-6313 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-09-09 13:15:00 UTC |
| Updated | 2021-07-21 11:39:00 UTC |
| Description | SAP NetWeaver Application Server JAVA(XML Forms) versions 7.30, 7.31, 7.40, 7.50 does not sufficiently encode user controlled inputs, which allows an authenticated User with special roles to store malicious content, that when accessed by a victim, can perform malicious actions by executing JavaScript, leading to Stored Cross-Site Scripting. |
Risk And Classification
Problem Types: CWE-79 | CWE-116
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Sap | Netweaver Application Server Java | 7.30 | All | All | All |
| Application | Sap | Netweaver Application Server Java | 7.31 | All | All | All |
| Application | Sap | Netweaver Application Server Java | 7.40 | All | All | All |
| Application | Sap | Netweaver Application Server Java | 7.50 | All | All | All |
| Application | Sap | Netweaver Knowledge Management | 7.30 | All | All | All |
| Application | Sap | Netweaver Knowledge Management | 7.31 | All | All | All |
| Application | Sap | Netweaver Knowledge Management | 7.40 | All | All | All |
| Application | Sap | Netweaver Knowledge Management | 7.50 | All | All | All |
| Application | Sap | Netweaver Knowledge Management | 7.30 | All | All | All |
| Application | Sap | Netweaver Knowledge Management | 7.31 | All | All | All |
| Application | Sap | Netweaver Knowledge Management | 7.40 | All | All | All |
| Application | Sap | Netweaver Knowledge Management | 7.50 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| SAP Security Patch Day – September 2020 - Product Security Response at SAP - Community Wiki | MISC | wiki.scn.sap.com | Vendor Advisory |
| launchpad.support.sap.com | MISC | launchpad.support.sap.com | Permissions Required |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 87515 SAP NetWeaver AS for Java Stored Cross-Site Scripting (XSS) Vulnerability