Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

CVE-2020-6193Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver (Knowledge Management ICE Service), SAP security note 2873012

SAP Note 2873012

SAP security note 2873012, “[CVE-2020-6193] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver (Knowledge Management ICE Service)”. Below are the symptom, SAP recommended solution and the affected software components.

Description

Symptom

SAP NetWeaver (Knowledge Management ICE Service) allows an unauthenticated attacker to execute malicious scripts, leading to a Reflected Cross-Site Scripting (XSS) vulnerability.

Some well-known impacts of XSS vulnerabilities include:

  • Defacement: Non-permanently deface or modify displayed content from a website.
  • Credential Theft: Steal authentication information of the user, such as data relating to their current session.
  • User Impersonation: Impersonate the user and access all information with the same rights as the target user.

Solution

  • Remove Obsolete Functionality: Obsolete ICE functionality is removed from the Knowledge Management ICE Service.
  • Apply Support Packages and Patches: Implement the Support Packages and Patches referenced by this SAP Note.

CVSS

Score 6.1 Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

References

  • CVE-2020-6193

Affected components

  • Enterprise Portal > Enterprise Portal – Knowledge Management and Collaboration > Content Management > Content Exchange (EP-KM-CM-ICE)
  • Affected Versions: 7.30, 7.31, 7.40, 7.50

Full note on SAP: SAP Support Launchpad note 2873012

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More