CVE-2020-6246: XSS
SAP NetWeaver AS ABAP Business Server Pages Test Application SBSPEXTTABLE, versions 700, 701, 702, 730, 731, 740, 750, 751, 752, 753, 754, does not sufficiently encode user-controlled inputs, resulting in reflected Cross-Site Scripting (XSS) vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-6246?
CVE-2020-6246 is a vulnerability in SAP NetWeaver AS ABAP Business Server Pages Test Application SBSPEXT_TABLE, versions 700, 701, 702, 730, 731, 740, 750, 751, 752, 753, 754, that allows for reflected Cross-Site Scripting (XSS) attacks.
What is the severity of CVE-2020-6246?
CVE-2020-6246 has a severity level of medium with a score of 6.1.
How does CVE-2020-6246 affect SAP NetWeaver AS ABAP Business Server Pages?
CVE-2020-6246 affects SAP NetWeaver AS ABAP Business Server Pages versions 700, 701, 702, 730, 731, 740, 750, 751, 752, 753, 754 by allowing for reflected XSS attacks due to insufficient encoding of user-controlled inputs.
How can I fix CVE-2020-6246?
To fix CVE-2020-6246, it is recommended to update SAP NetWeaver AS ABAP Business Server Pages to a patched version that addresses the XSS vulnerability. Additionally, follow the recommendations provided by SAP in their security notes and documentation.
Where can I find more information about CVE-2020-6246?
You can find more information about CVE-2020-6246 in the SAP Support Portal under the following links: [SAP Note 2878935](https://launchpad.support.sap.com/#/notes/2878935) and [SAP Wiki page](https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=547426775).