CVE-2020-26820
SAP NetWeaver AS JAVA, versions - 7.20, 7.30, 7.31, 7.40, 7.50, allows an attacker who is authenticated as an administrator to use the administrator console, to expose unauthenticated access to the file system and upload a malicious file.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (3.91%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
SAP NetWeaver AS JAVA, versions - 7.20, 7.30, 7.31, 7.40, 7.50, allows an attacker who is authenticated as an administrator to use the administrator console, to expose unauthenticated access to the file system and upload a malicious file. The attacker or another user can then use a separate mechanism to execute OS commands through the uploaded file leading to Privilege Escalation and completely compromise the confidentiality, integrity and availability of the server operating system and any application running on it.
- CVSS 3.1
- 7.2 HIGHCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 3.91% probability · 90th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-434
- Affected
- sap/netweaver application server java
- Source
- cna@sap.com
References
- http://packetstormsecurity.com/files/162086/SAP-Java-OS-Remote-Code-Execution.htmlThird Party Advisory, VDB Entry
- http://seclists.org/fulldisclosure/2021/Apr/7Mailing List, Third Party Advisory
- https://launchpad.support.sap.com/#/notes/2979062Permissions Required, Vendor Advisory
- https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=562725571Vendor Advisory
- http://packetstormsecurity.com/files/162086/SAP-Java-OS-Remote-Code-Execution.htmlThird Party Advisory, VDB Entry
- http://seclists.org/fulldisclosure/2021/Apr/7Mailing List, Third Party Advisory
- https://launchpad.support.sap.com/#/notes/2979062Permissions Required, Vendor Advisory
- https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=562725571Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.