First published: Tue Jul 14 2020(Updated: )
SAP NetWeaver (ABAP Server) and ABAP Platform, versions 731, 740, 750, allows an attacker with admin privileges to access certain files which should otherwise be restricted, leading to Information Disclosure.
Credit: cna@sap.com
Affected Software | Affected Version | How to fix |
---|---|---|
SAP ABAP Platform | =7.31 | |
SAP ABAP Platform | =7.40 | |
SAP ABAP Platform | =7.50 | |
SAP NetWeaver Application Server ABAP | =731 | |
SAP NetWeaver Application Server ABAP | =740 | |
SAP NetWeaver Application Server ABAP | =750 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-6280 is a vulnerability in SAP NetWeaver (ABAP Server) and ABAP Platform versions 731, 740, and 750 that allows an attacker with admin privileges to access certain files, leading to information disclosure.
CVE-2020-6280 has a severity rating of medium with a CVSS score of 2.7.
SAP NetWeaver (ABAP Server) versions 731, 740, and 750, as well as ABAP Platform versions 7.31, 7.40, and 7.50 are affected by CVE-2020-6280.
An attacker with admin privileges can exploit CVE-2020-6280 to access restricted files.
Yes, you can find more information about CVE-2020-6280 in the SAP Support Portal and the SAP Community Network Wiki.