First published: Tue Nov 10 2020(Updated: )
SAP NetWeaver AS ABAP (Web Dynpro), versions - 731, 740, 750, 751, 752, 753, 754, 755, 782, allows an authenticated user to access Web Dynpro components, which reveals sensitive system information that would otherwise be restricted to highly privileged users because of missing authorization, resulting in Information Disclosure.
Credit: cna@sap.com
Affected Software | Affected Version | How to fix |
---|---|---|
SAP NetWeaver Application Server for ABAP | =731 | |
SAP NetWeaver Application Server for ABAP | =740 | |
SAP NetWeaver Application Server for ABAP | =750 | |
SAP NetWeaver Application Server for ABAP | =751 | |
SAP NetWeaver Application Server for ABAP | =752 | |
SAP NetWeaver Application Server for ABAP | =753 | |
SAP NetWeaver Application Server for ABAP | =754 | |
SAP NetWeaver Application Server for ABAP | =755 | |
SAP NetWeaver Application Server for ABAP | =782 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-26818 has a medium severity rating due to the potential for exposing sensitive system information.
To fix CVE-2020-26818, apply the security patches provided by SAP for the affected NetWeaver AS ABAP versions.
CVE-2020-26818 affects SAP NetWeaver AS ABAP versions 731, 740, 750, 751, 752, 753, 754, 755, and 782.
CVE-2020-26818 is an authorization vulnerability that allows authenticated users to access Web Dynpro components.
The potential impacts of CVE-2020-26818 include unauthorized access to sensitive system information restricted to highly privileged users.