CVE-2020-26826: Malicious File Upload
Published Dec 9, 2020
·Updated
Process Integration Monitoring of SAP NetWeaver AS JAVA, versions - 7.31, 7.40, 7.50, allows an attacker to upload any file (including script files) without proper file format validation, leading to Unrestricted File Upload.
Affected Software
3 affected components
SAP NetWeaver Application Server Java=7.31
SAP NetWeaver Application Server Java=7.40
SAP NetWeaver Application Server Java=7.50
Event History
Dec 9, 2020
CVE Published
via MITRE·04:30 PM
Data Sourced
via MITRE·04:30 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID of this security vulnerability?
The vulnerability ID is CVE-2020-26826.
2
What is the title of this security vulnerability?
The title of this security vulnerability is 'Process Integration Monitoring of SAP NetWeaver AS JAVA versions - 7.31 7.40 7.50 allows an attacker…'
3
What is the severity of CVE-2020-26826?
The severity of CVE-2020-26826 is medium.
4
Which versions of SAP NetWeaver AS JAVA are affected by CVE-2020-26826?
CVE-2020-26826 affects SAP NetWeaver AS JAVA versions 7.31, 7.40, and 7.50.
5
How does CVE-2020-26826 work?
CVE-2020-26826 allows an attacker to upload any file (including script files) without proper file format validation, leading to Unrestricted File Upload.