CVE-2020-6287
Description
SAP NetWeaver AS JAVA (LM Configuration Wizard), versions - 7.30, 7.31, 7.40, 7.50, does not perform an authentication check which allows an attacker without prior authentication to execute configuration tasks to perform critical actions against the SAP Java system, including the ability to create an administrative user, and therefore compromising Confidentiality, Integrity and Availability of the system, leading to Missing Authentication Check.
Summary dbcve.org
SAP NetWeaver AS JAVA LM Configuration Wizard versions 7.30-7.50 lacks authentication checks on certain endpoints, allowing unauthenticated attackers to execute critical configuration tasks. Attackers can create new administrative users and fully compromise the system.
Mitigation
Apply SAP security patches for CVE-2020-6287 immediately. If patches are unavailable, restrict network access to the LM Configuration Wizard ports until remediation is possible.