CVE-2020-6313
MEDIUMSAP NetWeaver Application Server JAVA/XML Forms <7.50 - XSS
Title source: llmDescription
SAP NetWeaver Application Server JAVA(XML Forms) versions 7.30, 7.31, 7.40, 7.50 does not sufficiently encode user controlled inputs, which allows an authenticated User with special roles to store malicious content, that when accessed by a victim, can perform malicious actions by executing JavaScript, leading to Stored Cross-Site Scripting.
References (2)
Core 2
Core References
Vendor Advisory x_refsource_misc
https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=557449700
Permissions Required x_refsource_misc
https://launchpad.support.sap.com/#/notes/2953112
Scores
CVSS v3
6.5
EPSS
0.0030
EPSS Percentile
53.0%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Details
CWE
CWE-79
CWE-116
Status
published
Products (4)
sap/netweaver_application_server_java
7.30
sap/netweaver_application_server_java
7.31
sap/netweaver_application_server_java
7.40
sap/netweaver_application_server_java
7.50
Published
Sep 09, 2020
Tracked Since
Feb 18, 2026