CVE-2020-6287

NVD Published Date: July 14, 2020 at 01:15 PM
NVD Last Modified: April 28, 2022 at 06:57 PM
Download Patch
Vulnerability ID
CVE-2020-6287
Severity
CRITICAL
Severity Score
10.0
Summary
SAP NetWeaver AS JAVA (LM Configuration Wizard), versions - 7.30, 7.31, 7.40, 7.50, does not perform an authentication check which allows an attacker without prior authentication to execute configuration tasks to perform critical actions against the SAP Java system, including the ability to create an administrative user, and therefore compromising Confidentiality, Integrity and Availability of the system, leading to Missing Authentication Check.
Mitigation and Patches
-
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
CWE ID
CWE-306

Recent Publish

CVE-2020-1350

KB5002653

KB5002654

CVE-2020-14871

CVE-2021-22893

KB5044062

See More ...

See SecOps Solution
in action

Schedule Demo