Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

CVE-2020-6284 Cross-Site Scripting (XSS) in SAP NetWeaver (Knowledge Management), SAP security note 2928635

SAP Note 2928635

SAP security note 2928635, “[CVE-2020-6284] Cross-Site Scripting (XSS) in SAP NetWeaver (Knowledge Management)”. Below are the symptom, SAP recommended solution and the affected software components.

Description

Symptom

UPDATE 27th October 2020: This note has been re-released with updated ‘Correction instruction’ information for the release NetWeaver 7.50 SP12.

SAP NetWeaver Knowledge Management (KM) allows the automatic execution of script content in a stored file due to inadequate filtering with the accessing user’s privileges. If the accessing user has administrative privileges, then the execution of the script content could result in complete compromise of system confidentiality, integrity, and availability.

Solution

Malicious resource execution in SAP NetWeaver Knowledge Management is fixed now.

Reason and prerequisites

Reason: The stored file is automatically executed without checking for authorization.

Prerequisite: The malicious attack file has been previously uploaded.

CVSS

Score 9.0 Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H

References

Affected components

  • KMC-CM from 7.30 to 7.50

Full note on SAP: SAP Support Launchpad note 2928635

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More