SAP security note 2928635, “[CVE-2020-6284] Cross-Site Scripting (XSS) in SAP NetWeaver (Knowledge Management)”. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
UPDATE 27th October 2020: This note has been re-released with updated ‘Correction instruction’ information for the release NetWeaver 7.50 SP12.
SAP NetWeaver Knowledge Management (KM) allows the automatic execution of script content in a stored file due to inadequate filtering with the accessing user’s privileges. If the accessing user has administrative privileges, then the execution of the script content could result in complete compromise of system confidentiality, integrity, and availability.
Solution
Malicious resource execution in SAP NetWeaver Knowledge Management is fixed now.
Reason and prerequisites
Reason: The stored file is automatically executed without checking for authorization.
Prerequisite: The malicious attack file has been previously uploaded.
CVSS
Score 9.0 Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
References
- Files cannot be opened on portal from SAP KM – Note 2964558
- Q&A for SAP Security Note 2928635 – Note 2957979
- Security measures to protect malicious file uploading and opening in KM – Note 2932212
- Central Note: SAP NetWeaver 7.5 SP20 EP Core (Application Platform) – Note 2993476
- Central Note for NetWeaver 7.31 SP28 Enterprise Portal – Note 2968177
- Central Note: SAP NetWeaver 7.5 SP19 EP Core (Application Platform) – Note 2925000
Affected components
- KMC-CM from 7.30 to 7.50
Full note on SAP: SAP Support Launchpad note 2928635
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
