CVE-2020-6205
Key Information:
- Vendor
- SAP
- Vendor
- CVE Published:
- 10 March 2020
Summary
SAP NetWeaver AS ABAP Business Server Pages (Smart Forms), SAP_BASIS versions- 7.00, 7.01, 7.02, 7.10, 7.11, 7.30, 7.31, 7.40, 7.50, 7.51, 7.52, 7.53, 7.54; does not sufficiently encode user controlled inputs, allowing an unauthenticated attacker to non-permanently deface or modify displayed content and/or steal authentication information of the user and/or impersonate the user and access all information with the same rights as the target user, leading to Reflected Cross Site Scripting Vulnerability.
Affected Version(s)
SAP NetWeaver Application Server ABAP (Smart Forms) - SAP_BASIS < 7.00 < 7.00
SAP NetWeaver Application Server ABAP (Smart Forms) - SAP_BASIS < 7.01 < 7.01
SAP NetWeaver Application Server ABAP (Smart Forms) - SAP_BASIS < 7.02 < 7.02
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved