CVE-2020-6202: Input Validation
SAP NetWeaver Application Server Java (User Management Engine), versions- 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50; does not sufficiently validate the LDAP data source configuration XML document accepted from an untrusted source, leading to Missing XML Validation.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-6202?
The severity of CVE-2020-6202 is high with a severity value of 7.2.
What is the vulnerability in SAP NetWeaver Application Server Java (User Management Engine)?
The vulnerability in SAP NetWeaver Application Server Java (User Management Engine) is a missing XML validation issue.
Which versions of SAP NetWeaver Application Server Java are affected by CVE-2020-6202?
Versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, and 7.50 of SAP NetWeaver Application Server Java are affected by CVE-2020-6202.
How does CVE-2020-6202 impact the security of SAP NetWeaver Application Server Java?
CVE-2020-6202 allows an attacker to exploit the missing XML validation to manipulate LDAP data source configuration, potentially leading to unauthorized access or other security breaches.
How can I fix CVE-2020-6202 in SAP NetWeaver Application Server Java?
To fix CVE-2020-6202 in SAP NetWeaver Application Server Java, apply the necessary security patches provided by SAP and ensure proper XML validation of the LDAP data source configuration.