CVE-2020-6282
Last modified
CVE-2020-6282 is a medium-severity vulnerability rated 5.8/10 on the CVSS scale. SAP NetWeaver AS JAVA (IIOP service) (SERVERCORE), versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, and SAP NetWeaver AS JAVA (IIOP service) (CORE-TOOLS), versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, allows an attacker to send a crafted request from a vulnerable web application. It is usually used to target internal systems behind firewalls that are normally inaccessible to an attacker from the external network, resulting in a Server-Side Request Forgery vulnerability.. EPSS estimates a 1.15% chance of exploitation in the next 30 days.
Description
SAP NetWeaver AS JAVA (IIOP service) (SERVERCORE), versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, and SAP NetWeaver AS JAVA (IIOP service) (CORE-TOOLS), versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, allows an attacker to send a crafted request from a vulnerable web application. It is usually used to target internal systems behind firewalls that are normally inaccessible to an attacker from the external network, resulting in a Server-Side Request Forgery vulnerability.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Sap | Netweaver Application Server Java | 7.10 |
| Sap | Netweaver Application Server Java | 7.11 |
| Sap | Netweaver Application Server Java | 7.20 |
| Sap | Netweaver Application Server Java | 7.30 |
| Sap | Netweaver Application Server Java | 7.31 |
| Sap | Netweaver Application Server Java | 7.40 |
| Sap | Netweaver Application Server Java | 7.50 |
References
- https://launchpad.support.sap.com/#/notes/2896025Permissions Required, Vendor Advisory
- https://launchpad.support.sap.com/#/notes/2896025Permissions Required, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2020-6282?
How severe is CVE-2020-6282?
How do I fix CVE-2020-6282?
How Strix Helps
- One Click Account Takeover in GranolaHow a notification link broke out of Electron and led to a one-click account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2020
- CVE-2020-6275SAP Netweaver AS ABAP, versions 700, 701, 702, 710, 711, 730…9.8
- CVE-2020-6276SAP Business Objects Business Intelligence Platform (bipodat…6.1
- CVE-2020-6278SAP Business Objects Business Intelligence Platform (BI Laun…5.4
- CVE-2020-6279Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2020-6280SAP NetWeaver (ABAP Server) and ABAP Platform, versions 731,…2.7
- CVE-2020-6281SAP Business Objects Business Intelligence Platform (BI Laun…6.1
- CVE-2020-6283SAP Fiori Launchpad does not sufficiently encode user contro…6.1
- CVE-2020-6284SAP NetWeaver (Knowledge Management), versions - 7.30, 7.31,…9
- CVE-2020-6285SAP NetWeaver - XML Toolkit for JAVA (ENGINEAPI) (versions- …6.5
- CVE-2020-6286The insufficient input path validation of certain parameter …5.3
- CVE-2020-6287SAP NetWeaver AS JAVA (LM Configuration Wizard), versions - …10
- CVE-2020-6288SAP Business Objects Business Intelligence Platform (Web Int…5.3
Are you affected by CVE-2020-6282?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
