CVE-2020-6287 KEV
10.0
CRITICAL · CVSS 3.1 · EPSS 94.7% (pctl 100)
Patch first
On CISA KEV — known exploited in the wild, due 2022-05-03.
Description
SAP NetWeaver AS JAVA (LM Configuration Wizard), versions - 7.30, 7.31, 7.40, 7.50, does not perform an authentication check which allows an attacker without prior authentication to execute configuration tasks to perform critical actions against the SAP Java system, including the ability to create an administrative user, and therefore compromising Confidentiality, Integrity and Availability of the system, leading to Missing Authentication Check.
Scoring
| CVSS | 10.0 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
| EPSS | 94.72% — more likely to be exploited than 100% of all CVEs |
| Weakness | CWE-306 |
| On CISA KEV | yes — remediate by 2022-05-03 |
| Public exploit | none known |
| Published | 2020-07-14 |
| Last modified | 2026-06-17 |
CISA KEV
| Name | SAP NetWeaver Missing Authentication for Critical Function Vulnerability |
|---|---|
| Added | 2021-11-03 |
| Due | 2022-05-03 |
| Vendor / product | SAP / NetWeaver |
| Ransomware use | none reported |
Affected (1)
| Vendor | Product |
|---|---|
| sap | netweaver application server java |
References
- http://packetstormsecurity.com/files/162085/SAP-JAVA-Configuration-Task-Execution.html
- http://seclists.org/fulldisclosure/2021/Apr/6
- https://launchpad.support.sap.com/#/notes/2934135
- https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=552599675
- https://www.onapsis.com/recon-sap-cyber-security-vulnerability
- http://packetstormsecurity.com/files/162085/SAP-JAVA-Configuration-Task-Execution.html
- http://seclists.org/fulldisclosure/2021/Apr/6
- https://launchpad.support.sap.com/#/notes/2934135
- https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=552599675
- https://www.onapsis.com/recon-sap-cyber-security-vulnerability
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-6287
→ the Explorer · watch your stack · NVD