CVE-2020-6282: SSRF
SAP NetWeaver AS JAVA (IIOP service) (SERVERCORE), versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, and SAP NetWeaver AS JAVA (IIOP service) (CORE-TOOLS), versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, allows an attacker to send a crafted request from a vulnerable web application. It is usually used to target internal systems behind firewalls that are normally inaccessible to an attacker from the external network, resulting in a Server-Side Request Forgery vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-6282?
The severity of CVE-2020-6282 is medium.
Which versions of SAP NetWeaver AS JAVA are affected by this vulnerability?
Versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, and 7.50 of SAP NetWeaver AS JAVA are affected by this vulnerability.
How can an attacker exploit CVE-2020-6282?
An attacker can exploit CVE-2020-6282 by sending a crafted request from a vulnerable web application.
What is the Common Weakness Enumeration (CWE) ID for this vulnerability?
The Common Weakness Enumeration (CWE) ID for this vulnerability is 918.
Are there any references available for CVE-2020-6282?
Yes, you can refer to the following links for more information: - [SAP Note 2896025](https://launchpad.support.sap.com/#/notes/2896025) - [SAP SCN Wiki](https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=552599675)