CVE-2020-6287
SAP NetWeaver AS JAVA (LM Configuration Wizard), versions - 7.30, 7.31, 7.40, 7.50, does not perform an authentication check which allows an...
Basic Information
- CVE State
- PUBLISHED
- Reserved Date
- January 08, 2020
- Published Date
- July 14, 2020
- Last Updated
- January 29, 2025
- Vendor
- SAP SE
- Product
- SAP NetWeaver AS JAVA (LM Configuration Wizard)
- Description
- SAP NetWeaver AS JAVA (LM Configuration Wizard), versions - 7.30, 7.31, 7.40, 7.50, does not perform an authentication check which allows an attacker without prior authentication to execute configuration tasks to perform critical actions against the SAP Java system, including the ability to create an administrative user, and therefore compromising Confidentiality, Integrity and Availability of the system, leading to Missing Authentication Check.
- Tags
- Exploitation
- active
- Automatable
- Yes
- Technical Impact
- total
CVSS Scores
CVSS v3.0
Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
SSVC Information
References
Known Exploited Vulnerability Information
Source | Added Date |
---|---|
CISA | 2021-11-03 00:00:00 UTC |
Scanner Integrations
Scanner | URL | Date Detected |
---|---|---|
Nuclei | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2020/CVE-2020-6287.yaml | 2025-04-26 00:00:00 UTC |
Potential Proof of Concepts
Warning: These PoCs have not been tested and could contain malware. Use at your own risk.
murataydemir/CVE-2020-6287
Type: github • Created: 2020-08-13 09:12:37 UTC • Stars: 13
Onapsis/CVE-2020-6287_RECON-scanner
Type: github • Created: 2020-07-21 01:22:45 UTC • Stars: 28
duc-nt/CVE-2020-6287-exploit
Type: github • Created: 2020-07-20 18:45:53 UTC • Stars: 96
Timeline
-
CVE ID Reserved
-
CVE Published to Public
-
Proof of Concept Exploit Available
-
Added to KEVIntel
-
Detected by Nuclei