SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityAnalyzed

CVE-2020-6287

SAP NetWeaver Missing Authentication for Critical Function Vulnerability

KEVCRITICAL 10.0EPSS 94.7%

Does this matter?

Known to be exploited in the wild (CISA KEV, CISA remediation deadline 3 May 2022). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.

Description

SAP NetWeaver AS JAVA (LM Configuration Wizard), versions - 7.30, 7.31, 7.40, 7.50, does not perform an authentication check which allows an attacker without prior authentication to execute configuration tasks to perform critical actions against the SAP Java system, including the ability to create an administrative user, and therefore compromising Confidentiality, Integrity and Availability of the system, leading to Missing Authentication Check.

CVSS 3.1
10.0 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
EPSS
94.72% probability · 100th percentile
CISA KEV
Listed 3 November 2021 · due 3 May 2022
Weakness
CWE-306
Affected
sap/netweaver application server java
Source
cna@sap.com

CISA notes

Apply updates per vendor instructions. https://nvd.nist.gov/vuln/detail/CVE-2020-6287

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.