CVE-2020-6275

CRITICAL

SAP NetWeaver AS ABAP 700-754 - Server-Side Request Forgery via Session Import/Export

Title source: llm
STIX 2.1

Description

SAP Netweaver AS ABAP, versions 700, 701, 702, 710, 711, 730, 731, 740, 750, 751, 752, 753, 754, are vulnerable for Server Side Request Forgery Attack where in an attacker can use inappropriate path names containing malicious server names in the import/export of sessions functionality and coerce the web server into authenticating with the malicious server. Furthermore, if NTLM is setup the attacker can compromise confidentiality, integrity and availability of the SAP database.

References (2)

Core 2
Core References
Permissions Required x_refsource_misc
https://launchpad.support.sap.com/#/notes/2912939

Scores

CVSS v3 9.8
EPSS 0.0046
EPSS Percentile 64.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-918
Status published
Products (13)
sap/netweaver_application_server_abap 700
sap/netweaver_application_server_abap 701
sap/netweaver_application_server_abap 702
sap/netweaver_application_server_abap 710
sap/netweaver_application_server_abap 711
sap/netweaver_application_server_abap 730
sap/netweaver_application_server_abap 731
sap/netweaver_application_server_abap 740
sap/netweaver_application_server_abap 750
sap/netweaver_application_server_abap 751
... and 3 more
Published Jun 10, 2020
Tracked Since Feb 18, 2026