CVE-2020-6224
Summary
| CVE | CVE-2020-6224 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-04-14 19:15:00 UTC |
| Updated | 2021-07-21 11:39:00 UTC |
| Description | SAP NetWeaver AS Java (HTTP Service), versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, allows an attacker with administrator privileges to access user sensitive data such as passwords in trace files, when the user logs in and sends request with login credentials, leading to Information Disclosure. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| launchpad.support.sap.com |
MISC |
launchpad.support.sap.com |
Permissions Required, Vendor Advisory |
| SAP Security Patch Day – April 2020 - Product Security Response at SAP - Community Wiki |
MISC |
wiki.scn.sap.com |
Vendor Advisory |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 87516 SAP NetWeaver AS for Java Information Disclosure Vulnerability