CVE-2020-26819
5.4MEDIUM
Key Information:
- Vendor
- SAP
- Vendor
- CVE Published:
- 10 November 2020
Summary
SAP NetWeaver AS ABAP (Web Dynpro), versions - 731, 740, 750, 751, 752, 753, 754, 755, 782, allows an authenticated user to access Web Dynpro components, that allows them to read and delete database logfiles because of Improper Access Control.
Affected Version(s)
SAP NetWeaver AS ABAP (Web Dynpro) < 731 < 731
SAP NetWeaver AS ABAP (Web Dynpro) < 740 < 740
SAP NetWeaver AS ABAP (Web Dynpro) < 750 < 750
References
CVSS V3.1
Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved