CRITICAL

CVE-2020-6287

Sap Netweaver Application Server Java 2020-07-14 CVSS v3.1
CVSS
10
KEV

Description

SAP NetWeaver AS JAVA (LM Configuration Wizard), versions - 7.30, 7.31, 7.40, 7.50, does not perform an authentication check which allows an attacker without prior authentication to execute configuration tasks to perform critical actions against the SAP Java system, including the ability to create an administrative user, and therefore compromising Confidentiality, Integrity and Availability of the system, leading to Missing Authentication Check.

Summary dbcve.org

SAP NetWeaver AS JAVA LM Configuration Wizard versions 7.30-7.50 lacks authentication checks on certain endpoints, allowing unauthenticated attackers to execute critical configuration tasks. Attackers can create new administrative users and fully compromise the system.

Mitigation

Apply SAP security patches for CVE-2020-6287 immediately. If patches are unavailable, restrict network access to the LM Configuration Wizard ports until remediation is possible.

Proof of Concept

Weakness (CWE)

CWE-306 Missing Authentication

EPSS Score

94.72%
Probability of exploitation in next 30 days
99.9th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE