SAP security note 2956398, “CVE-2020-6319 XSS Vulnerability in SAP NetWeaver AS Java”. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
SAP has released Security Note 2956398 addressing a Cross-Site Scripting (XSS) vulnerability identified as CVE-2020-6319 in SAP NetWeaver Application Server Java. This vulnerability allows an unauthenticated attacker to inject malicious JavaScript code, potentially compromising user sessions and impacting the confidentiality and integrity of the application.
An unauthenticated attacker can inject JavaScript blocks into web pages or URLs containing special symbols that are not properly encoded. This can lead to the theft of authentication information and limited impacts on application confidentiality and integrity.
Solution
To mitigate this vulnerability, it is essential to update the Application Server Java to a Service Package (SP) or release where the issue has been resolved.
CVSS
Score 6.1 Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
References
- SAP Note 2956398
- CVE-2020-6319 Details
Affected components
- SERVERCORE: 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50
Full note on SAP: SAP Support Launchpad note 2956398
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
