Lucene search

K
nvd[email protected]NVD:CVE-2020-6324
HistorySep 09, 2020 - 2:15 p.m.

CVE-2020-6324

2020-09-0914:15:12
CWE-79
web.nvd.nist.gov
7
sap netweaver
abap
reflected xss
cve-2020-6324

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

CVSS3

6.1

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

EPSS

0.001

Percentile

38.6%

SAP Netweaver AS ABAP(BSP Test Application sbspext_table), version-700,701,720,730,731,740,750,751,752,753,754,755, allows an unauthenticated attacker to send polluted URL to the victim, when the victim clicks on this URL, the attacker can read, modify the information available in the victimοΏ½s browser leading to Reflected Cross Site Scripting.

Affected configurations

Nvd
Node
sapnetweaver_as_abap_business_server_pagesMatch700
OR
sapnetweaver_as_abap_business_server_pagesMatch701
OR
sapnetweaver_as_abap_business_server_pagesMatch702
OR
sapnetweaver_as_abap_business_server_pagesMatch730
OR
sapnetweaver_as_abap_business_server_pagesMatch731
OR
sapnetweaver_as_abap_business_server_pagesMatch740
OR
sapnetweaver_as_abap_business_server_pagesMatch750
OR
sapnetweaver_as_abap_business_server_pagesMatch751
OR
sapnetweaver_as_abap_business_server_pagesMatch752
OR
sapnetweaver_as_abap_business_server_pagesMatch753
OR
sapnetweaver_as_abap_business_server_pagesMatch754
OR
sapnetweaver_as_abap_business_server_pagesMatch755
VendorProductVersionCPE
sapnetweaver_as_abap_business_server_pages700cpe:2.3:a:sap:netweaver_as_abap_business_server_pages:700:*:*:*:*:*:*:*
sapnetweaver_as_abap_business_server_pages701cpe:2.3:a:sap:netweaver_as_abap_business_server_pages:701:*:*:*:*:*:*:*
sapnetweaver_as_abap_business_server_pages702cpe:2.3:a:sap:netweaver_as_abap_business_server_pages:702:*:*:*:*:*:*:*
sapnetweaver_as_abap_business_server_pages730cpe:2.3:a:sap:netweaver_as_abap_business_server_pages:730:*:*:*:*:*:*:*
sapnetweaver_as_abap_business_server_pages731cpe:2.3:a:sap:netweaver_as_abap_business_server_pages:731:*:*:*:*:*:*:*
sapnetweaver_as_abap_business_server_pages740cpe:2.3:a:sap:netweaver_as_abap_business_server_pages:740:*:*:*:*:*:*:*
sapnetweaver_as_abap_business_server_pages750cpe:2.3:a:sap:netweaver_as_abap_business_server_pages:750:*:*:*:*:*:*:*
sapnetweaver_as_abap_business_server_pages751cpe:2.3:a:sap:netweaver_as_abap_business_server_pages:751:*:*:*:*:*:*:*
sapnetweaver_as_abap_business_server_pages752cpe:2.3:a:sap:netweaver_as_abap_business_server_pages:752:*:*:*:*:*:*:*
sapnetweaver_as_abap_business_server_pages753cpe:2.3:a:sap:netweaver_as_abap_business_server_pages:753:*:*:*:*:*:*:*
Rows per page:
1-10 of 121

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

CVSS3

6.1

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

EPSS

0.001

Percentile

38.6%

Related for NVD:CVE-2020-6324