CVE-2020-6225

9.1CRITICAL

Key Information:

Summary

SAP NetWeaver (Knowledge Management), versions (KMC-CM - 7.00, 7.01, 7.02, 7.30, 7.31, 7.40, 7.50 and KMC-WPC 7.30, 7.31, 7.40, 7.50), does not sufficiently validate path information provided by users, thus characters representing traverse to parent directory are passed through to the file APIs, allowing the attacker to overwrite, delete, or corrupt arbitrary files on the remote server, leading to Path Traversal.

Affected Version(s)

SAP NetWeaver (Knowledge Management) (KMC-CM) < 7.00 < 7.00

SAP NetWeaver (Knowledge Management) (KMC-CM) < 7.01 < 7.01

SAP NetWeaver (Knowledge Management) (KMC-CM) < 7.02 < 7.02

References

CVSS V3.1

Score:
9.1
Severity:
CRITICAL
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.