VYPR

Knowledge Management

by SAP

CVEs (3)

  • CVE-2020-6225HigApr 14, 2020
    risk 0.57cvss 8.8epss 0.01

    SAP NetWeaver (Knowledge Management), versions (KMC-CM - 7.00, 7.01, 7.02, 7.30, 7.31, 7.40, 7.50 and KMC-WPC 7.30, 7.31, 7.40, 7.50), does not sufficiently validate path information provided by users, thus characters representing traverse to parent directory are passed through…

  • CVE-2021-21488MedMar 9, 2021
    risk 0.42cvss 6.5epss 0.01

    Knowledge Management versions 7.01, 7.02, 7.30, 7.31, 7.40, 7.50 allows a remote attacker with basic privileges to deserialize user-controlled data without verification, leading to insecure deserialization which triggers the attacker’s code, therefore impacting Availability.

  • CVE-2020-6293MedAug 12, 2020
    risk 0.42cvss 6.5epss 0.01

    SAP NetWeaver (Knowledge Management), versions - 7.30, 7.31, 7.40, 7.50, allows an unauthenticated attacker to upload a malicious file and also to access, modify or make unavailable existing files but the impact is limited to the files themselves and is restricted by other…