CVE-2020-6224: Medium severity SAP NetWeaver Application Server Java vulnerability
SAP NetWeaver AS Java (HTTP Service), versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, allows an attacker with administrator privileges to access user sensitive data such as passwords in trace files, when the user logs in and sends request with login credentials, leading to Information Disclosure.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-6224?
CVE-2020-6224 is a vulnerability in SAP NetWeaver AS Java (HTTP Service) versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, and 7.50 that allows an attacker with administrator privileges to access user sensitive data.
How can an attacker exploit CVE-2020-6224?
An attacker with administrator privileges can exploit CVE-2020-6224 by accessing user sensitive data, such as passwords, in trace files when the user logs in and sends requests with login credentials.
What is the severity of CVE-2020-6224?
CVE-2020-6224 has a severity score of 6.2, indicating a medium severity.
Which versions of SAP NetWeaver AS Java are affected by CVE-2020-6224?
Versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, and 7.50 of SAP NetWeaver AS Java are affected by CVE-2020-6224.
How can I fix CVE-2020-6224?
To fix CVE-2020-6224, it is recommended to apply the necessary patches or updates provided by SAP.