CVE-2020-6366: Input Validation
SAP NetWeaver (Compare Systems) versions - 7.20, 7.30, 7.40, 7.50, does not sufficiently validate uploaded XML documents. An attacker with administrative privileges can retrieve arbitrary files including files on OS level from the server and/or can execute a denial-of-service.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-6366?
CVE-2020-6366 is rated as a high-severity vulnerability due to its potential for remote file retrieval and denial-of-service attacks.
How do I fix CVE-2020-6366?
To fix CVE-2020-6366, it is recommended to apply the latest patches provided by SAP for the affected versions of NetWeaver Compare Systems.
Which versions of SAP software are affected by CVE-2020-6366?
CVE-2020-6366 affects SAP NetWeaver Compare Systems versions 7.20, 7.30, 7.31, 7.40, and 7.50.
What could an attacker achieve by exploiting CVE-2020-6366?
An attacker exploiting CVE-2020-6366 can retrieve sensitive files from the server or initiate a denial-of-service condition.
Is user authentication a mitigating factor for CVE-2020-6366?
While user authentication may restrict access, CVE-2020-6366 can still be exploited if an attacker has administrative privileges.