Junglewise Threat Intelligence

CVE-2020-6287: SAP NetWeaver Missing Authentication for Critical Function Vulnerability

CVE-2020-6287 · Severity: critical · CVSS 10 · Exploited in the wild · Published 2021-11-03

Technologies: SAP NetWeaver. Vendors: SAP SE, SAP.

Executive brief

SAP NetWeaver AS JAVA (LM Configuration Wizard) fails to perform authentication checks, allowing unauthenticated remote attackers to execute configuration tasks. This vulnerability enables the creation of administrative users, leading to a complete compromise of system confidentiality, integrity, and availability.

Affected products

  • SAP SE NetWeaver AS JAVA (LM Configuration Wizard) 7.30, 7.31, 7.40, 7.50

Timeline

  • 2020-07-14: disclosed: Initial analysis by NIST and vendor advisory published.
  • 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog.
  • 2021-11-03: exploited: Confirmed as exploited in the wild.

Related threats