peter bassill · operator
$ cve CVE-2020-26829 JSON

CVE-2020-26829

10.0
CRITICAL · CVSS 3.1 · EPSS 4.8% (pctl 92)

In your normal cycle

Critical by CVSS (10), but no sign of active exploitation.

Description

SAP NetWeaver AS JAVA (P2P Cluster Communication), versions - 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, allows arbitrary connections from processes because of missing authentication check, that are outside the cluster and even outside the network segment dedicated for the internal cluster communication. As result, an unauthenticated attacker can invoke certain functions that would otherwise be restricted to system administrators only, including access to system administration functions or shutting down the system completely.

Scoring

CVSS10.0 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
EPSS4.77% — more likely to be exploited than 92% of all CVEs
WeaknessCWE-306
On CISA KEVno
Public exploitnone known
Published2020-12-09
Last modified2026-06-17

Affected (1)

VendorProduct
sapnetweaver application server java

References

→ the Explorer  ·  watch your stack  ·  NVD