CVE-2020-6287: SAP NetWeaver Missing Authentication for Critical Function Vulnerability
SAP NetWeaver AS JAVA (LM Configuration Wizard), versions - 7.30, 7.31, 7.40, 7.50, does not perform an authentication check which allows an attacker without prior authentication to execute configuration tasks to perform critical actions against the SAP Java system, including the ability to create an administrative user, and therefore compromising Confidentiality, Integrity and Availability of the system, leading to Missing Authentication Check.
Other sources
SAP NetWeaver Application Server Java Platforms contains a missing authentication for critical function vulnerability allowing unauthenticated access to execute configuration tasks and create administrative users.
— CISA
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of this SAP NetWeaver vulnerability?
The vulnerability ID is CVE-2020-6287.
What is the title of this SAP NetWeaver vulnerability?
The title of this vulnerability is SAP NetWeaver Missing Authentication for Critical Function Vulnerability.
What is the severity of CVE-2020-6287?
The severity of CVE-2020-6287 is critical.
Which versions of SAP NetWeaver AS JAVA are affected by this vulnerability?
SAP NetWeaver AS JAVA versions 7.30, 7.31, 7.40, and 7.50 are affected by this vulnerability.
How does this vulnerability impact the SAP Java system?
This vulnerability allows an attacker without prior authentication to execute configuration tasks and perform critical actions against the SAP Java system, including the ability to create a...