CVE-2020-6287
קריטית 10.0 מנוצלת בשטח (KEV)
ניצול פעיל מאומת — קטלוג CISA KEV
- שם
- SAP NetWeaver Missing Authentication for Critical Function Vulnerability
- נוסף לקטלוג
- יעד טיפול (פדרלי)
- פעולה נדרשת
- Apply updates per vendor instructions.
תיאור (מקור, אנגלית)
SAP NetWeaver AS JAVA (LM Configuration Wizard), versions - 7.30, 7.31, 7.40, 7.50, does not perform an authentication check which allows an attacker without prior authentication to execute configuration tasks to perform critical actions against the SAP Java system, including the ability to create an administrative user, and therefore compromising Confidentiality, Integrity and Availability of the system, leading to Missing Authentication Check.
מדדים
- CVSS 3.1
-
10.0 (CRITICAL)
מקור הציון: NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H - EPSS — סבירות ניצול
- 95% (אחוזון 100) נכון ל-24/7/2026
- CWE
- CWE-306
מוצרים מושפעים
sap: netweaver application server java
קישורים
- https://launchpad.support.sap.com/#/notes/2934135 Permissions RequiredVendor Advisory
- https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=552599675 Broken LinkVendor Advisory
- https://launchpad.support.sap.com/#/notes/2934135 Permissions RequiredVendor Advisory
- https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=552599675 Broken LinkVendor Advisory
- http://packetstormsecurity.com/files/162085/SAP-JAVA-Configuration-Task-Execut… Third Party AdvisoryVDB Entry
- http://seclists.org/fulldisclosure/2021/Apr/6 Mailing ListThird Party Advisory
- https://www.onapsis.com/recon-sap-cyber-security-vulnerability Third Party Advisory
- http://packetstormsecurity.com/files/162085/SAP-JAVA-Configuration-Task-Execut… Third Party AdvisoryVDB Entry
- http://seclists.org/fulldisclosure/2021/Apr/6 Mailing ListThird Party Advisory
- https://www.onapsis.com/recon-sap-cyber-security-vulnerability Third Party Advisory