First published: Wed Jun 10 2020(Updated: )
SAP NetWeaver AS ABAP Business Server Pages Test Application SBSPEXT_TABLE, versions 700, 701, 702, 730, 731, 740, 750, 751, 752, 753, 754, does not sufficiently encode user-controlled inputs, resulting in reflected Cross-Site Scripting (XSS) vulnerability.
Credit: cna@sap.com
Affected Software | Affected Version | How to fix |
---|---|---|
SAP NetWeaver AS ABAP Business Server Pages | =700 | |
SAP NetWeaver AS ABAP Business Server Pages | =701 | |
SAP NetWeaver AS ABAP Business Server Pages | =702 | |
SAP NetWeaver AS ABAP Business Server Pages | =730 | |
SAP NetWeaver AS ABAP Business Server Pages | =731 | |
SAP NetWeaver AS ABAP Business Server Pages | =740 | |
SAP NetWeaver AS ABAP Business Server Pages | =750 | |
SAP NetWeaver AS ABAP Business Server Pages | =751 | |
SAP NetWeaver AS ABAP Business Server Pages | =752 | |
SAP NetWeaver AS ABAP Business Server Pages | =753 | |
SAP NetWeaver AS ABAP Business Server Pages | =754 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-6246 is a vulnerability in SAP NetWeaver AS ABAP Business Server Pages Test Application SBSPEXT_TABLE, versions 700, 701, 702, 730, 731, 740, 750, 751, 752, 753, 754, that allows for reflected Cross-Site Scripting (XSS) attacks.
CVE-2020-6246 has a severity level of medium with a score of 6.1.
CVE-2020-6246 affects SAP NetWeaver AS ABAP Business Server Pages versions 700, 701, 702, 730, 731, 740, 750, 751, 752, 753, 754 by allowing for reflected XSS attacks due to insufficient encoding of user-controlled inputs.
To fix CVE-2020-6246, it is recommended to update SAP NetWeaver AS ABAP Business Server Pages to a patched version that addresses the XSS vulnerability. Additionally, follow the recommendations provided by SAP in their security notes and documentation.
You can find more information about CVE-2020-6246 in the SAP Support Portal under the following links: [SAP Note 2878935](https://launchpad.support.sap.com/#/notes/2878935) and [SAP Wiki page](https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=547426775).