SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2020-6367

There is a reflected cross site scripting vulnerability in SAP NetWeaver Composite Application Framework, versions - 7.20, 7.30, 7.31, 7.40, 7.50.

MEDIUM 6.1EPSS 0.83%

Does this matter?

Lower severity and a low EPSS score (0.83%). Track it; it rarely justifies an emergency change on its own.

Description

There is a reflected cross site scripting vulnerability in SAP NetWeaver Composite Application Framework, versions - 7.20, 7.30, 7.31, 7.40, 7.50. An unauthenticated attacker can trick an unsuspecting authenticated user to click on a malicious link. The end users browser has no way to know that the script should not be trusted, and will execute the script, resulting in sensitive information being disclosed or modified.

CVSS 3.1
6.1 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
EPSS
0.83% probability · 55th percentile
CISA KEV
Not listed
Weakness
CWE-79
Affected
sap/netweaver composite application framework
Source
cna@sap.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.