Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

CVE-2020-6326 Cross-Site Scripting (XSS) vulnerabilities in SAP NetWeaver AS Java, SAP security note 2953112

SAP Note 2953112
SAP Security Note
Medium priority

SAP security note 2953112, "[CVE-2020-6326] Cross-Site Scripting (XSS) vulnerabilities in SAP NetWeaver AS Java", is a program error note released on September 8, 2020. Below are the symptom, SAP recommended solution and the affected software components.

ComponentEnterprise Portal > Enterprise Portal – Knowledge Management and Collaboration > Content Management > CM User Interface
CategoryProgram error
PriorityCorrection with medium priority
TypeSAP Security Note
Version5
StatusReleased for Customer
Released onSeptember 8, 2020
LanguageEnglish

Description

Symptom

This Security Note addresses stored cross-site scripting (XSS) vulnerabilities identified in SAP NetWeaver Application Server for Java (CVE-2020-6326, CVE-2020-6313), specifically within the Knowledge Management UI and XML forms. An authenticated attacker can exploit these vulnerabilities to execute arbitrary JavaScript, potentially extracting or modifying restricted information.

Solution

Apply the relevant support packages and patches as referenced in this SAP Note. The URL parameters have been properly encoded to prevent successful XSS attacks.

CVSS

Score 5.4 Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

References

Affected components

  • KMC-CM: Versions 7.30, 7.31, 7.40, 7.50

Full note on SAP: SAP Support Launchpad note 2953112

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More