CVE-2020-6287
SAP NetWeaver Missing Authentication for Critical Function Vulnerability
Does this matter?
Known to be exploited in the wild (CISA KEV, CISA remediation deadline 3 May 2022). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.
Description
SAP NetWeaver AS JAVA (LM Configuration Wizard), versions - 7.30, 7.31, 7.40, 7.50, does not perform an authentication check which allows an attacker without prior authentication to execute configuration tasks to perform critical actions against the SAP Java system, including the ability to create an administrative user, and therefore compromising Confidentiality, Integrity and Availability of the system, leading to Missing Authentication Check.
- CVSS 3.1
- 10.0 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
- EPSS
- 94.72% probability · 100th percentile
- CISA KEV
- Listed 3 November 2021 · due 3 May 2022
- Weakness
- CWE-306
- Affected
- sap/netweaver application server java
- Source
- cna@sap.com
CISA notes
Apply updates per vendor instructions. https://nvd.nist.gov/vuln/detail/CVE-2020-6287
References
- http://packetstormsecurity.com/files/162085/SAP-JAVA-Configuration-Task-Execution.htmlThird Party Advisory, VDB Entry
- http://seclists.org/fulldisclosure/2021/Apr/6Mailing List, Third Party Advisory
- https://launchpad.support.sap.com/#/notes/2934135Permissions Required, Vendor Advisory
- https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=552599675Broken Link, Vendor Advisory
- https://www.onapsis.com/recon-sap-cyber-security-vulnerabilityThird Party Advisory
- http://packetstormsecurity.com/files/162085/SAP-JAVA-Configuration-Task-Execution.htmlThird Party Advisory, VDB Entry
- http://seclists.org/fulldisclosure/2021/Apr/6Mailing List, Third Party Advisory
- https://launchpad.support.sap.com/#/notes/2934135Permissions Required, Vendor Advisory
- https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=552599675Broken Link, Vendor Advisory
- https://www.onapsis.com/recon-sap-cyber-security-vulnerabilityThird Party Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-6287US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.