Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2020-6293

Опубликовано: 12 авг. 2020
Источник: nvd
CVSS3: 7.3
CVSS3: 6.5
CVSS2: 6.4
EPSS Низкий

Описание

SAP NetWeaver (Knowledge Management), versions - 7.30, 7.31, 7.40, 7.50, allows an unauthenticated attacker to upload a malicious file and also to access, modify or make unavailable existing files but the impact is limited to the files themselves and is restricted by other policies such as access control lists and other upload file size restrictions, leading to Unrestricted File Upload.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:sap:netweaver_knowledge_management:7.30:*:*:*:*:*:*:*
cpe:2.3:a:sap:netweaver_knowledge_management:7.31:*:*:*:*:*:*:*
cpe:2.3:a:sap:netweaver_knowledge_management:7.40:*:*:*:*:*:*:*
cpe:2.3:a:sap:netweaver_knowledge_management:7.50:*:*:*:*:*:*:*

EPSS

Процентиль: 54%
0.0031
Низкий

7.3 High

CVSS3

6.5 Medium

CVSS3

6.4 Medium

CVSS2

Дефекты

CWE-434

Связанные уязвимости

github
больше 3 лет назад

SAP NetWeaver (Knowledge Management), versions - 7.30, 7.31, 7.40, 7.50, allows an unauthenticated attacker to upload a malicious file and also to access, modify or make unavailable existing files but the impact is limited to the files themselves and is restricted by other policies such as access control lists and other upload file size restrictions, leading to Unrestricted File Upload.

CVSS3: 7.3
fstec
больше 5 лет назад

Уязвимость компонента Knowledge Management программной интеграционной платформы SAP NetWeaver, позволяющая нарушителю получить доступ, изменить или сделать недоступными существующие файлы

EPSS

Процентиль: 54%
0.0031
Низкий

7.3 High

CVSS3

6.5 Medium

CVSS3

6.4 Medium

CVSS2

Дефекты

CWE-434