Beveiligingsadvies

CVE-2020-6323

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2020-10-15 01:45:27
Laatst bijgewerkt 2024-08-04 08:55:22
Toegewezen door sap
CVSS-score geen score
Status PUBLISHED

Beschrijving

SAP NetWeaver Enterprise Portal (Fiori Framework Page) versions - 7.50, 7.31, 7.40, does not sufficiently encode user-controlled inputs and allows an attacker on a valid session to create an XSS that will be both reflected immediately and also be persisted and returned in further access to the system, resulting in Cross Site Scripting.