Rewterz

Rewterz Threat Alert – Gorgon APT Using Maldoc Campaign in India

August 12, 2020
Rewterz

Rewterz Threat Advisory – CVE-2020-10055 – ICS: Siemens Desigo CC

August 13, 2020

Rewterz Threat Advisory – CVE-2020-6284 – SAP Netweaver (Knowledge Management) Cross-Site Scripting (XSS) vulnerability

Severity

High

Analysis Summary

SAP NetWeaver (Knowledge Management) allows the automatic execution of script content in a stored file due to inadequate filtering with the accessing user’s privileges. If the accessing user has administrative privileges, then the execution of the script content could result in complete compromise of system confidentiality, integrity and availability, leading to Stored Cross Site Scripting.

Impact

Cross-Site Scripting

Affected Vendors

SAP

Affected Products

  • SAP NetWeaver version 7.30
  • SAP NetWeaver version 7.31
  • SAP NetWeaver version 7.40
  • SAP NetWeaver version 7.50

Remediation

Refer to SAP Note for the respective patches.

SAP Note# 2928635

Reading this advisory was a good start.

Make it a habit.

Rewterz publishes threat advisories ahead of mainstream cybersecurity media, informed by an AI-Native Autonomous SOC that sees regional threat actor activity in real time. Subscribe to receive each new advisory as it publishes, plus a monthly Middle East threat landscape brief drawn from our own SOC telemetry. For teams evaluating their detection coverage, a 30-minute consultation with a senior analyst is also available, at your pace, when you're ready.