Server-Side Request Forgery Vulnerability in SAP NetWeaver AS JAVA
CVE-2020-6282
Key Information:
- Vendor
SAP
- Status
- Vendor
- CVE Published:
- 14 July 2020
What is CVE-2020-6282?
SAP NetWeaver AS JAVA, specifically targeting the IIOP service and CORE-TOOLS versions from 7.10 to 7.50, is susceptible to a server-side request forgery (SSRF) vulnerability. This weakness allows attackers to send specially crafted requests that can manipulate internal system resources, which are typically protected by firewalls. By exploiting this vulnerability, an attacker could gain unauthorized access to internal systems, posing a risk to data security and integrity.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
SAP NetWeaver AS JAVA (IIOP service) (CORE-TOOLS) < 7.10 < 7.10
SAP NetWeaver AS JAVA (IIOP service) (CORE-TOOLS) < 7.11 < 7.11
SAP NetWeaver AS JAVA (IIOP service) (CORE-TOOLS) < 7.20 < 7.20
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved