VYPR

Netweaver Knowledge Management

by SAP

CVEs (6)

  • CVE-2020-6284CriAug 12, 2020
    risk 0.59cvss 9.0epss 0.02

    SAP NetWeaver (Knowledge Management), versions - 7.30, 7.31, 7.40, 7.50, allows the automatic execution of script content in a stored file due to inadequate filtering with the accessing user's privileges. If the accessing user has administrative privileges, then the execution of…

  • CVE-2021-21488MedMar 9, 2021
    risk 0.42cvss 6.5epss 0.01

    Knowledge Management versions 7.01, 7.02, 7.30, 7.31, 7.40, 7.50 allows a remote attacker with basic privileges to deserialize user-controlled data without verification, leading to insecure deserialization which triggers the attacker’s code, therefore impacting Availability.

  • CVE-2020-6293MedAug 12, 2020
    risk 0.42cvss 6.5epss 0.01

    SAP NetWeaver (Knowledge Management), versions - 7.30, 7.31, 7.40, 7.50, allows an unauthenticated attacker to upload a malicious file and also to access, modify or make unavailable existing files but the impact is limited to the files themselves and is restricted by other…

  • CVE-2021-33707MedAug 10, 2021
    risk 0.40cvss 6.1epss 0.02

    SAP NetWeaver Knowledge Management allows remote attackers to redirect users to arbitrary websites and conduct phishing attacks via a URL stored in a component. This could enable the attacker to compromise the user's confidentiality and integrity.

  • CVE-2020-6193MedFeb 12, 2020
    risk 0.40cvss 6.1epss 0.01

    SAP NetWeaver (Knowledge Management ICE Service), versions 7.30, 7.31, 7.40, 7.50, allows an unauthenticated attacker to execute malicious scripts leading to Reflected Cross-Site Scripting (XSS) vulnerability.

  • CVE-2020-6326MedSep 9, 2020
    risk 0.35cvss 5.4epss 0.01

    SAP NetWeaver (Knowledge Management), version-7.30,7.31,7.40,7.50, allows an authenticated attacker to create malicious links in the UI, when clicked by victim, will execute arbitrary java scripts thus extracting or modifying information otherwise restricted leading to Stored…