CVE-2020-6287
CRITICAL KEV NUCLEISAP NetWeaver AS JAVA - Missing Authentication Check
Title source: llmDescription
SAP NetWeaver AS JAVA (LM Configuration Wizard), versions - 7.30, 7.31, 7.40, 7.50, does not perform an authentication check which allows an attacker without prior authentication to execute configuration tasks to perform critical actions against the SAP Java system, including the ability to create an administrative user, and therefore compromising Confidentiality, Integrity and Availability of the system, leading to Missing Authentication Check.
Exploits (8)
nomisec
WORKING POC
1 stars
by dylvie · poc
https://github.com/dylvie/CVE-2020-6287_SAP-NetWeaver-bypass-auth
nomisec
SUSPICIOUS
1 stars
by ynsmroztas · poc
https://github.com/ynsmroztas/CVE-2020-6287-Sap-Add-User
metasploit
WORKING POC
by Pablo Artuso, Dmitry Chastuhin, Spencer McIntyre · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/auxiliary/admin/sap/cve_2020_6287_ws_add_user.rb
Nuclei Templates (1)
SAP NetWeaver AS JAVA 7.30-7.50 - Remote Admin Addition
CRITICALby dwisiswant0
Shodan:
http.favicon.hash:-266008933
FOFA:
icon_hash=-266008933
References (6)
Scores
CVSS v3
10.0
EPSS
0.9439
EPSS Percentile
100.0%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Details
CISA KEV
2021-11-03
VulnCheck KEV
2021-04-08
InTheWild.io
2021-07-23
ENISA EUVD
EUVD-2020-27437
CWE
CWE-306
Status
published
Products (4)
sap/netweaver_application_server_java
7.30
sap/netweaver_application_server_java
7.31
sap/netweaver_application_server_java
7.40
sap/netweaver_application_server_java
7.50
Published
Jul 14, 2020
KEV Added
Nov 03, 2021
Tracked Since
Feb 18, 2026