5.5
CVSSv2

CVE-2020-6366

Published: 20/10/2020 Updated: 22/10/2020
CVSS v2 Base Score: 5.5 | Impact Score: 4.9 | Exploitability Score: 8
CVSS v3 Base Score: 6.5 | Impact Score: 5.2 | Exploitability Score: 1.2
VMScore: 490
Vector: AV:N/AC:L/Au:S/C:P/I:N/A:P

Vulnerability Summary

SAP NetWeaver (Compare Systems) versions - 7.20, 7.30, 7.40, 7.50, does not sufficiently validate uploaded XML documents. An attacker with administrative privileges can retrieve arbitrary files including files on OS level from the server and/or can execute a denial-of-service.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

sap netweaver compare systems 7.20

sap netweaver compare systems 7.30

sap netweaver compare systems 7.31

sap netweaver compare systems 7.40

sap netweaver compare systems 7.50