CVE-2020-26829
10.0
CRITICAL · CVSS 3.1 · EPSS 4.8% (pctl 92)
In your normal cycle
Critical by CVSS (10), but no sign of active exploitation.
Description
SAP NetWeaver AS JAVA (P2P Cluster Communication), versions - 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, allows arbitrary connections from processes because of missing authentication check, that are outside the cluster and even outside the network segment dedicated for the internal cluster communication. As result, an unauthenticated attacker can invoke certain functions that would otherwise be restricted to system administrators only, including access to system administration functions or shutting down the system completely.
Scoring
| CVSS | 10.0 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
| EPSS | 4.77% — more likely to be exploited than 92% of all CVEs |
| Weakness | CWE-306 |
| On CISA KEV | no |
| Public exploit | none known |
| Published | 2020-12-09 |
| Last modified | 2026-06-17 |
Affected (1)
| Vendor | Product |
|---|---|
| sap | netweaver application server java |
References
- http://packetstormsecurity.com/files/163166/SAP-Netweaver-JAVA-7.50-Missing-Authorization.html
- http://seclists.org/fulldisclosure/2021/Jun/33
- https://launchpad.support.sap.com/#/notes/2974774
- https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=564757079
- http://packetstormsecurity.com/files/163166/SAP-Netweaver-JAVA-7.50-Missing-Authorization.html
- http://seclists.org/fulldisclosure/2021/Jun/33
- https://launchpad.support.sap.com/#/notes/2974774
- https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=564757079
→ the Explorer · watch your stack · NVD