VYPR
Medium severity5.4NVD Advisory· Published Feb 12, 2020· Updated Jun 17, 2026

CVE-2020-6185

CVE-2020-6185

Description

Under certain conditions ABAP Online Community in SAP NetWeaver (SAP_BASIS version 7.40) and SAP S/4HANA (SAP_BASIS versions 7.50, 7.51, 7.52, 7.53, 7.54), allows an authenticated attacker to store a malicious payload which results in Stored Cross Site Scripting vulnerability.

Affected products

10
  • SAP/Netweaver2 versions
    cpe:2.3:a:sap:netweaver:7.40:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:sap:netweaver:7.40:*:*:*:*:*:*:*
    • (no CPE)range: 7.40
  • SAP/S\/4hana5 versions
    cpe:2.3:a:sap:s\/4hana:7.50:*:*:*:*:*:*:*+ 4 more
    • cpe:2.3:a:sap:s\/4hana:7.50:*:*:*:*:*:*:*
    • cpe:2.3:a:sap:s\/4hana:7.51:*:*:*:*:*:*:*
    • cpe:2.3:a:sap:s\/4hana:7.52:*:*:*:*:*:*:*
    • cpe:2.3:a:sap:s\/4hana:7.53:*:*:*:*:*:*:*
    • cpe:2.3:a:sap:s\/4hana:7.54:*:*:*:*:*:*:*
  • SAP/S/4HANAllm-fuzzy
    Range: 7.50, 7.51, 7.52, 7.53, 7.54
  • SAP SE/SAP NetWeaver (SAP Basis)v5
    Range: = 7.40
  • SAP SE/SAP S/4HANA (SAP Basis)v5
    Range: = 7.50

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.