Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

CVE-2020-6319 Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver AS Java, SAP security note 2956398

SAP Note 2956398

SAP security note 2956398, “CVE-2020-6319 XSS Vulnerability in SAP NetWeaver AS Java”. Below are the symptom, SAP recommended solution and the affected software components.

ComponentSAP NetWeaver Application Server Java

Description

Symptom

SAP has released Security Note 2956398 addressing a Cross-Site Scripting (XSS) vulnerability identified as CVE-2020-6319 in SAP NetWeaver Application Server Java. This vulnerability allows an unauthenticated attacker to inject malicious JavaScript code, potentially compromising user sessions and impacting the confidentiality and integrity of the application.

An unauthenticated attacker can inject JavaScript blocks into web pages or URLs containing special symbols that are not properly encoded. This can lead to the theft of authentication information and limited impacts on application confidentiality and integrity.

Solution

To mitigate this vulnerability, it is essential to update the Application Server Java to a Service Package (SP) or release where the issue has been resolved.

CVSS

Score 6.1 Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

References

Affected components

  • SERVERCORE: 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50

Full note on SAP: SAP Support Launchpad note 2956398

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More