CVE-2020-6203: Path Traversal
SAP NetWeaver UDDI Server (Services Registry), versions- 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50; allows an attacker to exploit insufficient validation of path information provided by users, thus characters representing 'traverse to parent directory' are passed through to the file APIs, leading to Path Traversal.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this SAP NetWeaver UDDI Server (Services Registry) vulnerability?
The vulnerability ID for this SAP NetWeaver UDDI Server (Services Registry) vulnerability is CVE-2020-6203.
What is the severity level of CVE-2020-6203?
The severity level of CVE-2020-6203 is critical with a severity value of 9.1.
Which versions of SAP NetWeaver UDDI Server (Services Registry) are affected by this vulnerability?
Versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, and 7.50 of SAP NetWeaver UDDI Server (Services Registry) are affected by this vulnerability.
How can an attacker exploit this vulnerability?
An attacker can exploit this vulnerability by exploiting insufficient validation of path information provided by users, leading to the passing of 'traverse to parent directory' characters to the file APIs.
Is there a fix available for CVE-2020-6203?
Yes, SAP has released security notes and patches to address the vulnerability. Please refer to the SAP support portal for more information.