CVE-2020-6313: XSS
Published Sep 9, 2020
·Updated
SAP NetWeaver Application Server JAVA(XML Forms) versions 7.30, 7.31, 7.40, 7.50 does not sufficiently encode user controlled inputs, which allows an authenticated User with special roles to store malicious content, that when accessed by a victim, can perform malicious actions by executing JavaScript, leading to Stored Cross-Site Scripting.
Affected Software
4 affected components
SAP NetWeaver Application Server Java=7.30
SAP NetWeaver Application Server Java=7.31
SAP NetWeaver Application Server Java=7.40
SAP NetWeaver Application Server Java=7.50
Event History
Sep 9, 2020
CVE Published
via MITRE·12:43 PM
Data Sourced
via MITRE·12:43 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID of this issue?
The vulnerability ID of this issue is CVE-2020-6313.
2
What is the severity of CVE-2020-6313?
The severity of CVE-2020-6313 is medium (6.5).
3
Which software versions are affected by CVE-2020-6313?
SAP NetWeaver Application Server JAVA(XML Forms) versions 7.30, 7.31, 7.40, and 7.50 are affected by CVE-2020-6313.
4
What is the CWE ID of CVE-2020-6313?
The CWE ID of CVE-2020-6313 is 116 and 79.
5
How can I fix CVE-2020-6313?
To fix CVE-2020-6313, apply the necessary patches or updates provided by SAP.