Unrestricted File Upload Vulnerability in SAP NetWeaver by SAP
CVE-2020-6293

7.3HIGH

Key Information:

Vendor
SAP
Vendor
CVE Published:
12 August 2020

Summary

SAP NetWeaver (Knowledge Management) versions 7.30, 7.31, 7.40, and 7.50 contain a vulnerability that allows unauthenticated attackers to upload malicious files to the server. This can lead to unauthorized access or modification of existing files. While the impact is primarily limited to the files themselves, it remains constrained by existing policies like access control lists and upload file size restrictions. Consequently, this risk highlights the need for robust security measures around file handling and upload functionalities to mitigate potential exploitation.

Affected Version(s)

SAP NetWeaver (Knowledge Management) < 7.30 < 7.30

SAP NetWeaver (Knowledge Management) < 7.31 < 7.31

SAP NetWeaver (Knowledge Management) < 7.40 < 7.40

References

CVSS V3.1

Score:
7.3
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.