CyberSec.Space Logo
Back to CVE Browser

CVE-2020-6275

CRITICAL
9.8
CVSS Severity Score
EPSS Score0.0220%
EPSS Percentile42.16th
PublishedJun 10, 2020
Last ModifiedNov 21, 2024

Vulnerability Description

SAP Netweaver AS ABAP, versions 700, 701, 702, 710, 711, 730, 731, 740, 750, 751, 752, 753, 754, are vulnerable for Server Side Request Forgery Attack where in an attacker can use inappropriate path names containing malicious server names in the import/export of sessions functionality and coerce the web server into authenticating with the malicious server. Furthermore, if NTLM is setup the attacker can compromise confidentiality, integrity and availability of the SAP database.

Affected Platforms (CPE)

πŸ“¦
Sap

Netweaver Application Server Abap

= 700
πŸ“¦
Sap

Netweaver Application Server Abap

= 701
πŸ“¦
Sap

Netweaver Application Server Abap

= 702
πŸ“¦
Sap

Netweaver Application Server Abap

= 710
πŸ“¦
Sap

Netweaver Application Server Abap

= 711
πŸ“¦
Sap

Netweaver Application Server Abap

= 730
πŸ“¦
Sap

Netweaver Application Server Abap

= 731
πŸ“¦
Sap

Netweaver Application Server Abap

= 740
πŸ“¦
Sap

Netweaver Application Server Abap

= 750
πŸ“¦
Sap

Netweaver Application Server Abap

= 751
πŸ“¦
Sap

Netweaver Application Server Abap

= 752
πŸ“¦
Sap

Netweaver Application Server Abap

= 753
πŸ“¦
Sap

Netweaver Application Server Abap

= 754

References & Advisories

Related Vulnerabilities