SAP Security Note
Medium priority
SAP security note 2953112, "[CVE-2020-6326] Cross-Site Scripting (XSS) vulnerabilities in SAP NetWeaver AS Java", is a program error note released on September 8, 2020. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
This Security Note addresses stored cross-site scripting (XSS) vulnerabilities identified in SAP NetWeaver Application Server for Java (CVE-2020-6326, CVE-2020-6313), specifically within the Knowledge Management UI and XML forms. An authenticated attacker can exploit these vulnerabilities to execute arbitrary JavaScript, potentially extracting or modifying restricted information.
Solution
Apply the relevant support packages and patches as referenced in this SAP Note. The URL parameters have been properly encoded to prevent successful XSS attacks.
CVSS
Score 5.4 Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
References
- 2993476 – Central Note: SAP NetWeaver 7.5 SP20 EP Core (Application Platform)
- 2968177 – Central Note for NetWeaver 7.31 SP28 Enterprise Portal
Affected components
- KMC-CM: Versions 7.30, 7.31, 7.40, 7.50
Full note on SAP: SAP Support Launchpad note 2953112
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
