CVE-2020-6184: XSS
Under certain conditions, ABAP Online Community in SAP NetWeaver (SAPBASIS version 7.40) and SAP S/4HANA (SAPBASIS versions 7.50, 7.51, 7.52, 7.53, 7.54), does not sufficiently encode user-controlled inputs, resulting in Reflected Cross-Site Scripting (XSS) vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-6184?
CVE-2020-6184 is a Reflected Cross-Site Scripting (XSS) vulnerability in ABAP Online Community in SAP NetWeaver and SAP S/4HANA.
What is the severity of CVE-2020-6184?
The severity of CVE-2020-6184 is medium.
Which software versions are affected by CVE-2020-6184?
CVE-2020-6184 affects SAP NetWeaver (SAP_BASIS version 7.40), and SAP S/4HANA (SAP_BASIS versions 7.50, 7.51, 7.52, 7.53, 7.54).
How does CVE-2020-6184 impact the affected software?
CVE-2020-6184 allows attackers to execute malicious scripts in the context of a user's browser, potentially leading to unauthorized actions or phishing attacks.
Is there a fix available for CVE-2020-6184?
Yes, SAP has released security notes and patches to address CVE-2020-6184. Please refer to the official SAP support portal for more information.