SAP NetWeaver KW Reflected Cross-Site Scripting

medium Web App Scanning Plugin ID 114111

Synopsis

SAP NetWeaver KW Reflected Cross-Site Scripting

Description

A security vulnerability has been discovered in the SAP Knowledge Warehouse - versions 7.30, 7.31, 7.40, 7.50. The usage of one SAP KW component within a Web browser enables unauthorized attackers to conduct XSS attacks, which might lead to disclose sensitive data.

Solution

Refer to the SAP advisory for mitigation options.

See Also

https://redrays.io/blog/cve-2021-42063-cross-site-scripting-xss-vulnerability-in-sap-knowledge-warehouse-sap-security-note-3102769/

Plugin Details

Severity: Medium

ID: 114111

Type: remote

Published: 11/22/2023

Updated: 11/22/2023

Scan Template: basic, full, pci, scan

Risk Information

VPR

Risk Factor: Medium

Score: 4.6

CVSS v2

Risk Factor: Medium

Base Score: 4.3

Vector: CVSS2#AV:N/AC:M/Au:N/C:N/I:P/A:N

CVSS Score Source: CVE-2021-42063

CVSS v3

Risk Factor: Medium

Base Score: 6.1

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

CVSS Score Source: CVE-2021-42063

Vulnerability Information

CPE: cpe:2.3:a:sap:knowledge_warehouse:*:*:*:*:*:*:*:*

Exploit Available: true

Exploit Ease: Exploits are available

Reference Information

CVE: CVE-2021-42063