CVE-2020-6190
Summary
| CVE | CVE-2020-6190 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-02-12 20:15:00 UTC |
| Updated | 2020-02-19 18:06:00 UTC |
| Description | Certain vulnerable endpoints in SAP NetWeaver AS Java (Heap Dump Application), versions 7.30, 7.31, 7.40, 7.50, provide valuable information about the system like hostname, server node and installation path that could be misused by an attacker leading to Information Disclosure. |
Risk And Classification
Problem Types: CWE-200
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Sap | Netweaver Application Server Java | 7.30 | All | All | All |
| Application | Sap | Netweaver Application Server Java | 7.31 | All | All | All |
| Application | Sap | Netweaver Application Server Java | 7.40 | All | All | All |
| Application | Sap | Netweaver Application Server Java | 7.50 | All | All | All |
| Application | Sap | Netweaver Application Server Java | 7.30 | All | All | All |
| Application | Sap | Netweaver Application Server Java | 7.31 | All | All | All |
| Application | Sap | Netweaver Application Server Java | 7.40 | All | All | All |
| Application | Sap | Netweaver Application Server Java | 7.50 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| launchpad.support.sap.com | MISC | launchpad.support.sap.com | Permissions Required, Vendor Advisory |
| SAP Security Patch Day – February 2020 - Product Security Response at SAP - Community Wiki | MISC | wiki.scn.sap.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.