Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2020-6284

Опубликовано: 12 авг. 2020
Источник: nvd
CVSS3: 9
CVSS3: 9
CVSS2: 8.5
EPSS Низкий

Описание

SAP NetWeaver (Knowledge Management), versions - 7.30, 7.31, 7.40, 7.50, allows the automatic execution of script content in a stored file due to inadequate filtering with the accessing user's privileges. If the accessing user has administrative privileges, then the execution of the script content could result in complete compromise of system confidentiality, integrity and availability, leading to Stored Cross Site Scripting.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:sap:netweaver_knowledge_management:7.30:*:*:*:*:*:*:*
cpe:2.3:a:sap:netweaver_knowledge_management:7.31:*:*:*:*:*:*:*
cpe:2.3:a:sap:netweaver_knowledge_management:7.40:*:*:*:*:*:*:*
cpe:2.3:a:sap:netweaver_knowledge_management:7.50:*:*:*:*:*:*:*

EPSS

Процентиль: 75%
0.00892
Низкий

9 Critical

CVSS3

9 Critical

CVSS3

8.5 High

CVSS2

Дефекты

CWE-79

Связанные уязвимости

github
больше 3 лет назад

SAP NetWeaver (Knowledge Management), versions - 7.30, 7.31, 7.40, 7.50, allows the automatic execution of script content in a stored file due to inadequate filtering with the accessing user's privileges. If the accessing user has administrative privileges, then the execution of the script content could result in complete compromise of system confidentiality, integrity and availability, leading to Stored Cross Site Scripting.

CVSS3: 9
fstec
больше 5 лет назад

Уязвимость компонента Knowledge Management программной интеграционной платформы SAP NetWeaver, позволяющая нарушителю осуществить межсайтовые сценарные атаки

EPSS

Процентиль: 75%
0.00892
Низкий

9 Critical

CVSS3

9 Critical

CVSS3

8.5 High

CVSS2

Дефекты

CWE-79