Executive brief
SAP NetWeaver AS JAVA (LM Configuration Wizard) fails to perform authentication checks, allowing unauthenticated remote attackers to execute configuration tasks. This vulnerability enables the creation of administrative users, leading to a complete compromise of system confidentiality, integrity, and availability.
Affected products
- SAP SE NetWeaver AS JAVA (LM Configuration Wizard) 7.30, 7.31, 7.40, 7.50
Timeline
- 2020-07-14: disclosed: Initial analysis by NIST and vendor advisory published.
- 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog.
- 2021-11-03: exploited: Confirmed as exploited in the wild.