First published: Tue Oct 20 2020(Updated: )
SAP NetWeaver (Compare Systems) versions - 7.20, 7.30, 7.40, 7.50, does not sufficiently validate uploaded XML documents. An attacker with administrative privileges can retrieve arbitrary files including files on OS level from the server and/or can execute a denial-of-service.
Credit: cna@sap.com
Affected Software | Affected Version | How to fix |
---|---|---|
Sap Netweaver Compare Systems | =7.20 | |
Sap Netweaver Compare Systems | =7.30 | |
Sap Netweaver Compare Systems | =7.31 | |
Sap Netweaver Compare Systems | =7.40 | |
Sap Netweaver Compare Systems | =7.50 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-6366 is rated as a high-severity vulnerability due to its potential for remote file retrieval and denial-of-service attacks.
To fix CVE-2020-6366, it is recommended to apply the latest patches provided by SAP for the affected versions of NetWeaver Compare Systems.
CVE-2020-6366 affects SAP NetWeaver Compare Systems versions 7.20, 7.30, 7.31, 7.40, and 7.50.
An attacker exploiting CVE-2020-6366 can retrieve sensitive files from the server or initiate a denial-of-service condition.
While user authentication may restrict access, CVE-2020-6366 can still be exploited if an attacker has administrative privileges.