Sap Netweaver Knowledge Management vulnerabilities

6 known vulnerabilities affecting sap/netweaver_knowledge_management.

Total CVEs
6
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1MEDIUM5

Vulnerabilities

Page 1 of 1
CVE-2021-33707MEDIUMCVSS 6.1v7.30v7.31+2 more2021-08-10
CVE-2021-33707 [MEDIUM] CWE-601 CVE-2021-33707: SAP NetWeaver Knowledge Management allows remote attackers to redirect users to arbitrary websites a SAP NetWeaver Knowledge Management allows remote attackers to redirect users to arbitrary websites and conduct phishing attacks via a URL stored in a component. This could enable the attacker to compromise the user's confidentiality and integrity.
nvd
CVE-2021-21488MEDIUMCVSS 6.5v7.01v7.02+4 more2021-03-09
CVE-2021-21488 [MEDIUM] CWE-502 CVE-2021-21488: Knowledge Management versions 7.01, 7.02, 7.30, 7.31, 7.40, 7.50 allows a remote attacker with basic Knowledge Management versions 7.01, 7.02, 7.30, 7.31, 7.40, 7.50 allows a remote attacker with basic privileges to deserialize user-controlled data without verification, leading to insecure deserialization which triggers the attacker’s code, therefore impacting Availability.
nvd
CVE-2020-6326MEDIUMCVSS 5.4v7.30v7.31+2 more2020-09-09
CVE-2020-6326 [MEDIUM] CWE-79 CVE-2020-6326: SAP NetWeaver (Knowledge Management), version-7.30,7.31,7.40,7.50, allows an authenticated attacker SAP NetWeaver (Knowledge Management), version-7.30,7.31,7.40,7.50, allows an authenticated attacker to create malicious links in the UI, when clicked by victim, will execute arbitrary java scripts thus extracting or modifying information otherwise restricted leading to Stored Cross Site Scripting.
nvd
CVE-2020-6284CRITICALCVSS 9.0v7.30v7.31+2 more2020-08-12
CVE-2020-6284 [CRITICAL] CWE-79 CVE-2020-6284: SAP NetWeaver (Knowledge Management), versions - 7.30, 7.31, 7.40, 7.50, allows the automatic execut SAP NetWeaver (Knowledge Management), versions - 7.30, 7.31, 7.40, 7.50, allows the automatic execution of script content in a stored file due to inadequate filtering with the accessing user's privileges. If the accessing user has administrative privileges, then the execution of the script content could result in complete compromise of system confide
nvd
CVE-2020-6293MEDIUMCVSS 6.5v7.30v7.31+2 more2020-08-12
CVE-2020-6293 [MEDIUM] CWE-434 CVE-2020-6293: SAP NetWeaver (Knowledge Management), versions - 7.30, 7.31, 7.40, 7.50, allows an unauthenticated a SAP NetWeaver (Knowledge Management), versions - 7.30, 7.31, 7.40, 7.50, allows an unauthenticated attacker to upload a malicious file and also to access, modify or make unavailable existing files but the impact is limited to the files themselves and is restricted by other policies such as access control lists and other upload file size restrictions,
nvd
CVE-2020-6193MEDIUMCVSS 6.1v7.30v7.31+2 more2020-02-12
CVE-2020-6193 [MEDIUM] CWE-79 CVE-2020-6193: SAP NetWeaver (Knowledge Management ICE Service), versions 7.30, 7.31, 7.40, 7.50, allows an unauthe SAP NetWeaver (Knowledge Management ICE Service), versions 7.30, 7.31, 7.40, 7.50, allows an unauthenticated attacker to execute malicious scripts leading to Reflected Cross-Site Scripting (XSS) vulnerability.
nvd