CVE-2020-6287

CRITICAL KEV NUCLEI

SAP NetWeaver AS JAVA - Missing Authentication Check

Title source: llm

Description

SAP NetWeaver AS JAVA (LM Configuration Wizard), versions - 7.30, 7.31, 7.40, 7.50, does not perform an authentication check which allows an attacker without prior authentication to execute configuration tasks to perform critical actions against the SAP Java system, including the ability to create an administrative user, and therefore compromising Confidentiality, Integrity and Availability of the system, leading to Missing Authentication Check.

Exploits (8)

nomisec WORKING POC 225 stars
by chipik · remote
https://github.com/chipik/SAP_RECON
nomisec WORKING POC 96 stars
by duc-nt · remote
https://github.com/duc-nt/CVE-2020-6287-exploit
nomisec SCANNER 28 stars
by Onapsis · remote
https://github.com/Onapsis/CVE-2020-6287_RECON-scanner
nomisec WORKING POC 13 stars
by murataydemir · remote
https://github.com/murataydemir/CVE-2020-6287
nomisec WORKING POC 1 stars
by dylvie · poc
https://github.com/dylvie/CVE-2020-6287_SAP-NetWeaver-bypass-auth
nomisec SUSPICIOUS 1 stars
by ynsmroztas · poc
https://github.com/ynsmroztas/CVE-2020-6287-Sap-Add-User
nomisec SCANNER
by qmakake · infoleak
https://github.com/qmakake/SAP_CVE-2020-6287_find_mandate
metasploit WORKING POC
by Pablo Artuso, Dmitry Chastuhin, Spencer McIntyre · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/auxiliary/admin/sap/cve_2020_6287_ws_add_user.rb

Nuclei Templates (1)

SAP NetWeaver AS JAVA 7.30-7.50 - Remote Admin Addition
CRITICALby dwisiswant0
Shodan: http.favicon.hash:-266008933
FOFA: icon_hash=-266008933

Scores

CVSS v3 10.0
EPSS 0.9439
EPSS Percentile 100.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Details

CISA KEV 2021-11-03
VulnCheck KEV 2021-04-08
InTheWild.io 2021-07-23
ENISA EUVD EUVD-2020-27437
CWE
CWE-306
Status published
Products (4)
sap/netweaver_application_server_java 7.30
sap/netweaver_application_server_java 7.31
sap/netweaver_application_server_java 7.40
sap/netweaver_application_server_java 7.50
Published Jul 14, 2020
KEV Added Nov 03, 2021
Tracked Since Feb 18, 2026