CRITICAL🚩 CISA KEV⚡ EXPLOIT🇵🇱 Wersja polska

CVE-2020-6287

CVSS 10.0v3.1pub. 2020-07-14upd. 2025-10-31

SAP NetWeaver AS JAVA (LM Configuration Wizard), versions - 7.30, 7.31, 7.40, 7.50, does not perform an authentication check which allows an attacker without prior authentication to execute configuration tasks to perform critical actions against the SAP Java system, including the ability to create an administrative user, and therefore compromising Confidentiality, Integrity and Availability of the system, leading to Missing Authentication Check.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
  • Sap Netweaver Application Server Java

    APP
    Sap
    7.307.317.407.50

CISA KEV — detailsi

Vendori
SAP
Producti
NetWeaver
Added to KEVi
November 3, 2021
Remediation deadline (US Federal)i
May 3, 2022(overdue)
Required action (CISA)i

Apply updates per vendor instructions.

CISA descriptioni

SAP NetWeaver Application Server Java Platforms contains a missing authentication for critical function vulnerability allowing unauthenticated access to execute configuration tasks and create administrative users.

🔴
IMMEDIATE ACTION
Actively exploited in the wild (CISA KEV). Patch immediately.
CISA DEADLINE: 3 maja 2022
CWE
References

Related vulnerabilities

CVE-2010-5326CRITICAL10.0⚠ KEVPL ✓same product

SAP NetWeaver AS Java — RCE przez Invoker Servlet bez uwierzytelnienia

CVE-2016-2386CRITICAL9.8⚠ KEVPL ✓same product

SQL Injection w serwerze UDDI SAP NetWeaver J2EE Engine 7.40

CVE-2024-22127CRITICAL9.1PL ✓same product

SAP NetWeaver AS Java – command injection przez upload pliku w Log Viewer

CVE-2023-40309CRITICAL9.8PL ✓same product

SAP CommonCryptoLib — brak weryfikacji autoryzacji, privilege escalation

CVE-2022-22532CRITICAL9.8PL ✓same product

SAP NetWeaver AS Java — nieautoryzowane wykonanie kodu przez błąd bufora HTTP