peter bassill · operator
$ cve CVE-2020-6287 JSON

CVE-2020-6287 KEV

10.0
CRITICAL · CVSS 3.1 · EPSS 94.7% (pctl 100)

Patch first

On CISA KEV — known exploited in the wild, due 2022-05-03.

Description

SAP NetWeaver AS JAVA (LM Configuration Wizard), versions - 7.30, 7.31, 7.40, 7.50, does not perform an authentication check which allows an attacker without prior authentication to execute configuration tasks to perform critical actions against the SAP Java system, including the ability to create an administrative user, and therefore compromising Confidentiality, Integrity and Availability of the system, leading to Missing Authentication Check.

Scoring

CVSS10.0 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
EPSS94.72% — more likely to be exploited than 100% of all CVEs
WeaknessCWE-306
On CISA KEVyes — remediate by 2022-05-03
Public exploitnone known
Published2020-07-14
Last modified2026-06-17

CISA KEV

NameSAP NetWeaver Missing Authentication for Critical Function Vulnerability
Added2021-11-03
Due2022-05-03
Vendor / productSAP / NetWeaver
Ransomware usenone reported

Affected (1)

VendorProduct
sapnetweaver application server java

References

→ the Explorer  ·  watch your stack  ·  NVD