CVE-2020-6299

MEDIUM

SAP NetWeaver <755 - Info Disclosure

Title source: llm
STIX 2.1

Description

SAP NetWeaver (ABAP Server) and ABAP Platform, versions - 740, 750, 751, 752, 753, 754, 755, allows a business user to access the list of users in the given system using value help, leading to Information Disclosure.

References (2)

Core 2
Core References
Permissions Required x_refsource_misc
https://launchpad.support.sap.com/#/notes/2941510

Scores

CVSS v3 4.3
EPSS 0.0023
EPSS Percentile 45.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Details

Status published
Products (12)
sap/abap_platform 740
sap/abap_platform 750
sap/abap_platform 751
sap/abap_platform 753
sap/abap_platform 754
sap/abap_platform 755
sap/netweaver_application_server_abap 740
sap/netweaver_application_server_abap 750
sap/netweaver_application_server_abap 751
sap/netweaver_application_server_abap 753
... and 2 more
Published Aug 12, 2020
Tracked Since Feb 18, 2026