CVE-2020-6326
Summary
| CVE | CVE-2020-6326 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-09-09 13:15:00 UTC |
| Updated | 2020-09-14 17:49:00 UTC |
| Description | SAP NetWeaver (Knowledge Management), version-7.30,7.31,7.40,7.50, allows an authenticated attacker to create malicious links in the UI, when clicked by victim, will execute arbitrary java scripts thus extracting or modifying information otherwise restricted leading to Stored Cross Site Scripting. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| SAP Security Patch Day – September 2020 - Product Security Response at SAP - Community Wiki |
MISC |
wiki.scn.sap.com |
Vendor Advisory |
| launchpad.support.sap.com |
MISC |
launchpad.support.sap.com |
Permissions Required |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 87513 SAP NetWeaver AS for Java Stored Cross-Site Scripting (XSS) Vulnerability