← All CVEs

CVE-2020-6287

critical · 10Actively exploited

On the CISA Known Exploited Vulnerabilities catalog

Apply updates per vendor instructions.

Added 2021-11-03Remediation due 2022-05-03

A public exploit / detection template exists

Weaponised detection is publicly available, which meaningfully raises real-world risk regardless of CVSS. nuclei-templates

SAP NetWeaver AS JAVA (LM Configuration Wizard), versions - 7.30, 7.31, 7.40, 7.50, does not perform an authentication check which allows an attacker without prior authentication to execute configuration tasks to perform critical actions against the SAP Java system, including the ability to create an administrative user, and therefore compromising Confidentiality, Integrity and Availability of the system, leading to Missing Authentication Check.

10
CVSS
94.7%
EPSS (exploit prob.)
100th
EPSS percentile
2020-07-14
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Weaknesses

CWE-306

Affected products

VendorProductAffected versions
sapnetweaver_application_server_java7.30
sapnetweaver_application_server_java7.31
sapnetweaver_application_server_java7.40
sapnetweaver_application_server_java7.50

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2020-6287