CVE Database
/

CVE-2020-6323

Back to search

CVE-2020-6323

Published: Oct 15, 2020

Modified: Aug 4, 2024

PUBLISHED

Description

SAP NetWeaver Enterprise Portal (Fiori Framework Page) versions - 7.50, 7.31, 7.40, does not sufficiently encode user-controlled inputs and allows an attacker on a valid session to create an XSS that will be both reflected immediately and also be persisted and returned in further access to the system, resulting in Cross Site Scripting.

VendorProductVersions

SAP SE

SAP NetWeaver Enterprise Portal (Fiori Framework Page)

affected
< 7.50
affected
< 7.31
affected
< 7.40

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now