CVE-2020-6263

CRITICAL

SAP NetWeaver AS Java - Auth Bypass

Title source: llm
STIX 2.1

Description

Standalone clients connecting to SAP NetWeaver AS Java via P4 Protocol, versions (SAP-JEECOR 7.00, 7.01; SERVERCOR 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50; CORE-TOOLS 7.00, 7.01, 7.02, 7.05, 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50) do not perform any authentication checks for operations that require user identity leading to Authentication Bypass.

References (2)

Core 2
Core References
Permissions Required x_refsource_misc
https://launchpad.support.sap.com/#/notes/2878568

Scores

CVSS v3 9.8
EPSS 0.0022
EPSS Percentile 45.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-306
Status published
Products (11)
sap/netweaver_application_server_java 7.00
sap/netweaver_application_server_java 7.01
sap/netweaver_application_server_java 7.02
sap/netweaver_application_server_java 7.05
sap/netweaver_application_server_java 7.10
sap/netweaver_application_server_java 7.11
sap/netweaver_application_server_java 7.20
sap/netweaver_application_server_java 7.30
sap/netweaver_application_server_java 7.31
sap/netweaver_application_server_java 7.40
... and 1 more
Published Jun 10, 2020
Tracked Since Feb 18, 2026