VYPR

NetWeaver Knowledge Management XMLEditor

by SAP

CVEs (3)

  • CVE-2018-2477HigNov 13, 2018
    risk 0.57cvss 8.8epss 0.02

    Knowledge Management (XMLForms) in SAP NetWeaver, versions 7.30, 7.31, 7.40 and 7.50 does not sufficiently validate an XML document accepted from an untrusted source.

  • CVE-2024-34685MedJul 9, 2024
    risk 0.40cvss 6.1epss 0.00

    Due to weak encoding of user-controlled input in SAP NetWeaver Knowledge Management XMLEditor which allows malicious scripts can be executed in the application, potentially leading to a Cross-Site Scripting (XSS) vulnerability. This has no impact on the availability of the…

  • CVE-2021-33707MedAug 10, 2021
    risk 0.40cvss 6.1epss 0.02

    SAP NetWeaver Knowledge Management allows remote attackers to redirect users to arbitrary websites and conduct phishing attacks via a URL stored in a component. This could enable the attacker to compromise the user's confidentiality and integrity.