There is a reflected cross site scripting vulnerability in SAP NetWeaver Composite Application Framework, versions - 7.20, 7.30, 7.31, 7.40, 7.50. An unauthenticated attacker can trick an unsuspecting authenticated user to click on a malicious link. The end users browser has no way to know that the script should not be trusted, and will execute the script, resulting in sensitive information being disclosed or modified.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: sap
Published: 2020-10-20T13:32:14
Updated: 2024-08-04T09:02:39.915Z
Reserved: 2020-01-08T00:00:00
Link: CVE-2020-6367
Vulnrichment
No data.
NVD
Status : Modified
Published: 2020-10-20T14:15:14.697
Modified: 2024-11-21T05:35:35.380
Link: CVE-2020-6367
Redhat
No data.