CVE-2020-6299: Medium severity sap abap vulnerability
Published Aug 12, 2020
·Updated
SAP NetWeaver (ABAP Server) and ABAP Platform, versions - 740, 750, 751, 752, 753, 754, 755, allows a business user to access the list of users in the given system using value help, leading to Information Disclosure.
Affected Software
12 affected components
SAP ABAP Platform=740
SAP ABAP Platform=750
SAP ABAP Platform=751
SAP ABAP Platform=753
SAP ABAP Platform=754
SAP ABAP Platform=755
SAP NetWeaver Application Server ABAP=740
SAP NetWeaver Application Server ABAP=750
SAP NetWeaver Application Server ABAP=751
SAP NetWeaver Application Server ABAP=753
SAP NetWeaver Application Server ABAP=754
SAP NetWeaver Application Server ABAP=755
Event History
Aug 12, 2020
CVE Published
via MITRE·01:43 PM
Data Sourced
via MITRE·01:43 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the SAP NetWeaver (ABAP Server) and ABAP Platform vulnerability?
It allows a business user to access the list of users in the given system using value help, leading to Information Disclosure.
2
What versions of SAP NetWeaver (ABAP Server) and ABAP Platform are affected?
Versions 740, 750, 751, 752, 753, 754, and 755 are affected.
3
What is the severity of vulnerability CVE-2020-6299?
The severity of CVE-2020-6299 is medium with a CVSS score of 4.3.
4
How can the SAP NetWeaver (ABAP Server) and ABAP Platform vulnerability be fixed?
Apply the necessary security patches provided by SAP.
5
Where can I find more information about the SAP NetWeaver (ABAP Server) and ABAP Platform vulnerability?
You can find more information at the following references: [Link 1](https://launchpad.support.sap.com/#/notes/2941510), [Link 2](https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=552603345).