CVE-2020-6286: Path Traversal
The insufficient input path validation of certain parameter in the web service of SAP NetWeaver AS JAVA (LM Configuration Wizard), versions - 7.30, 7.31, 7.40, 7.50, allows an unauthenticated attacker to exploit a method to download zip files to a specific directory, leading to Path Traversal.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-6286?
The severity of CVE-2020-6286 is medium with a severity score of 5.3.
How does CVE-2020-6286 affect SAP NetWeaver AS JAVA?
CVE-2020-6286 affects SAP NetWeaver AS JAVA versions 7.30, 7.31, 7.40, and 7.50.
What is the vulnerability exploited in CVE-2020-6286?
CVE-2020-6286 is a Path Traversal vulnerability.
How can an unauthenticated attacker exploit CVE-2020-6286?
An unauthenticated attacker can exploit CVE-2020-6286 by downloading zip files to a specific directory through a method in the web service of SAP NetWeaver AS JAVA (LM Configuration Wizard).
How can I fix CVE-2020-6286?
To fix CVE-2020-6286, update your SAP NetWeaver AS JAVA to a patched version provided by SAP.