CVE-2020-6287
Summary
| CVE | CVE-2020-6287 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-07-14 13:15:00 UTC |
| Updated | 2022-04-28 18:57:00 UTC |
| Description | SAP NetWeaver AS JAVA (LM Configuration Wizard), versions - 7.30, 7.31, 7.40, 7.50, does not perform an authentication check which allows an attacker without prior authentication to execute configuration tasks to perform critical actions against the SAP Java system, including the ability to create an administrative user, and therefore compromising Confidentiality, Integrity and Availability of the system, leading to Missing Authentication Check. |
Risk And Classification
EPSS: 0.947190000 probability, percentile 0.998490000 (date 2026-07-22)
CISA KEV: Listed on 2021-11-03; due 2022-05-03; ransomware use Unknown
Problem Types: CWE-306
CISA Known Exploited Vulnerability
| Vendor | SAP |
|---|---|
| Product | NetWeaver |
| Name | SAP NetWeaver Missing Authentication for Critical Function Vulnerability |
| Required Action | Apply updates per vendor instructions. |
| Notes | https://nvd.nist.gov/vuln/detail/CVE-2020-6287 |
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Sap | Netweaver Application Server Java | 7.30 | All | All | All |
| Application | Sap | Netweaver Application Server Java | 7.31 | All | All | All |
| Application | Sap | Netweaver Application Server Java | 7.40 | All | All | All |
| Application | Sap | Netweaver Application Server Java | 7.50 | All | All | All |
| Application | Sap | Netweaver Application Server Java | 7.30 | All | All | All |
| Application | Sap | Netweaver Application Server Java | 7.31 | All | All | All |
| Application | Sap | Netweaver Application Server Java | 7.40 | All | All | All |
| Application | Sap | Netweaver Application Server Java | 7.50 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| launchpad.support.sap.com | MISC | launchpad.support.sap.com | Permissions Required, Vendor Advisory |
| Full Disclosure: Onapsis Security Advisory 2021-0003: [CVE-2020-6287] - [SAP RECON] SAP JAVA: Unauthenticated execution of configuration tasks | FULLDISC | seclists.org | |
| SAP RECON Cybersecurity Vulnerability | Onapsis | MISC | www.onapsis.com | |
| SAP Security Patch Day – July 2020 - Product Security Response at SAP - Community Wiki | MISC | wiki.scn.sap.com | Vendor Advisory |
| SAP JAVA Configuration Task Execution ≈ Packet Storm | MISC | packetstormsecurity.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
| CISA Known Exploited Vulnerabilities catalog | CISA | www.cisa.gov | kev |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.