Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

CVE-2020-6293 Unrestricted File Upload in SAP NetWeaver (Knowledge Management), SAP security note 2938162

SAP Note 2938162

SAP security note 2938162, “[CVE-2020-6293] Unrestricted File Upload in SAP NetWeaver (Knowledge Management)”. Below are the symptom and SAP recommended solution.

Description

Symptom

SAP NetWeaver (Knowledge Management) allows an unauthenticated attacker to upload a file without requiring any user action. This can enable the attacker to access, modify, or make existing files unavailable. However, the impact is limited to the files themselves and is restricted by other policies such as access control lists and upload file size restrictions.

Solution

The affected functions have been updated to properly enforce access restrictions. To mitigate this vulnerability, implement the Support Packages and Patches referenced in this SAP Note.

For detailed information about the affected releases, refer to the “Support Packages & Patches” section of SAP Note 2938162.

References

CVSS

Score 7.3 Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

Full note on SAP: SAP Support Launchpad note 2938162

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More